exposure-scan

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads threat intelligence catalogs in JSON format from the official 'perplexityai/bumblebee' GitHub repository. These downloads are performed to update the local threat database and do not include executable scripts.
  • [COMMAND_EXECUTION]: Executes the 'bumblebee' binary (a Go-based security tool) to inventory system packages and match them against known exposure catalogs. It also recommends the user install this tool via 'go install'.
  • [DYNAMIC_EXECUTION]: Uses inline Python scripts within the bash wrapper to perform JSON schema validation on downloaded catalogs and to format the scan results for display.
  • [PERSISTENCE_MECHANISMS]: Provides instructions for the user to add the Go binary path to their shell profile (~/.zshrc) to ensure the 'bumblebee' command remains available. This is a standard configuration practice for Go-based tools.
  • [DATA_EXPOSURE_&_EXFILTRATION]: While the skill inventories installed packages to perform its function, it does not transmit this data to external servers; the matching occurs locally against the downloaded catalogs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 01:32 AM
Security Audit — agent-trust-hub — exposure-scan