cve-triage
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches vulnerability data from well-known authoritative sources including CISA (cisa.gov) and FIRST (api.first.org).
- [COMMAND_EXECUTION]: Executes standard command-line utilities for data processing and environment diagnostics, such as
jq,govulncheck,npm ls, andpip showin a legitimate context. - [PROMPT_INJECTION]: The skill processes untrusted scan data from sources like Snyk and Dependabot. Ingestion points: Phase 1 intake of scanner dumps. Boundary markers: Absent. Capability inventory:
curl,jq, and dependency management tools. Sanitization: Not explicitly implemented. Given the diagnostic nature of the skill, this is assessed as a low-risk surface.
Audit Metadata