cve-triage

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches vulnerability data from well-known authoritative sources including CISA (cisa.gov) and FIRST (api.first.org).
  • [COMMAND_EXECUTION]: Executes standard command-line utilities for data processing and environment diagnostics, such as jq, govulncheck, npm ls, and pip show in a legitimate context.
  • [PROMPT_INJECTION]: The skill processes untrusted scan data from sources like Snyk and Dependabot. Ingestion points: Phase 1 intake of scanner dumps. Boundary markers: Absent. Capability inventory: curl, jq, and dependency management tools. Sanitization: Not explicitly implemented. Given the diagnostic nature of the skill, this is assessed as a low-risk surface.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:30 PM
Security Audit — agent-trust-hub — cve-triage