grype-syft-sbom-scanner

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill documents the use of official Anchore open-source tools (Syft and Grype) for security auditing and compliance workflows. All commands and patterns provided are standard for these tools.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using syft and grype. These commands are used to inventory packages and scan for vulnerabilities in local files, directories, and container images, which aligns with the skill's primary security purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 12:22 PM
Security Audit — agent-trust-hub — grype-syft-sbom-scanner