snyk-agent-scan-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local skill directories to perform its analysis. 1. Ingestion points: Reads SKILL.md and files within the references/ directory using the Read and Glob tools. 2. Boundary markers: None. 3. Capability inventory: Possesses Read, Edit, Write, Bash, and Agent tools, which allows for file modification and command execution based on the processed content. 4. Sanitization: None. While this surface exists, it is inherent to the skill's purpose as a scanner and compliance tool.\n- [COMMAND_EXECUTION]: The skill utilizes the Bash tool (restricted to git, uv, and uvx) to run the snyk-agent-scan utility and manage project dependencies, which is necessary for its auditing functions.\n- [EXTERNAL_DOWNLOADS]: The skill setup includes the installation of the snyk-agent-scan tool via the uv package manager, which is a legitimate dependency for the skill's operation.
Audit Metadata