vuls-linux-cve-scanner
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references standard documentation and tool workflows for 'Vuls', an open-source vulnerability scanner, specifically linking to its official domain (vuls.io) and vulsctl-style Docker workflows. These are well-known industry resources.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly advises the user to 'Keep credentials outside the repository' and 'Do not store SSH private keys in the repository,' demonstrating a strong security posture in alignment with credential management best practices.
- [COMMAND_EXECUTION]: The skill provides example command-line instructions for the Vuls tool (e.g., vuls configtest, vuls scan, vuls report). These are limited to the intended functionality of the vulnerability scanner.
- [INDIRECT_PROMPT_INJECTION]: The skill defines report templates. While it processes data externally (vulnerability reports), it does not include instructions for automated tool output ingestion or processing that would lead to injection vulnerabilities.
Audit Metadata