exposure-scan
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads threat intelligence catalogs in JSON format from the official 'perplexityai/bumblebee' GitHub repository. These downloads are performed to update the local threat database and do not include executable scripts.
- [COMMAND_EXECUTION]: Executes the 'bumblebee' binary (a Go-based security tool) to inventory system packages and match them against known exposure catalogs. It also recommends the user install this tool via 'go install'.
- [DYNAMIC_EXECUTION]: Uses inline Python scripts within the bash wrapper to perform JSON schema validation on downloaded catalogs and to format the scan results for display.
- [PERSISTENCE_MECHANISMS]: Provides instructions for the user to add the Go binary path to their shell profile (~/.zshrc) to ensure the 'bumblebee' command remains available. This is a standard configuration practice for Go-based tools.
- [DATA_EXPOSURE_&_EXFILTRATION]: While the skill inventories installed packages to perform its function, it does not transmit this data to external servers; the matching occurs locally against the downloaded catalogs.
Audit Metadata