discover-attack-surface
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses several command-line utilities, including
javap,jar,unzip, and theopentaintCLI, to perform static analysis of project dependencies and bytecode. These operations are essential for the skill's stated purpose of auditing software security. - [COMMAND_EXECUTION]: Bundled shell and PowerShell scripts (
package-usages.shandpackage-usages.ps1) automate the extraction of method invocations from the project model. These scripts run locally and process project data without making external network connections.
Audit Metadata