sbom-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external SBOM and VEX files which could contain malicious instructions. However, it explicitly mitigates this with a dedicated 'Prompt Injection Safety Notice' instructing the agent to ignore any embedded commands. Evidence: Ingestion points include SBOM and VEX files; Boundary markers are present in the safety notice section; Capability inventory is limited to Read, Grep, and Glob; Sanitization includes explicit instructions to ignore data-driven overrides.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or dynamic execution were found. The skill does not download external scripts or packages.
  • [DATA_EXFILTRATION]: No patterns for data exfiltration or sensitive file exposure were identified. The allowed tools are limited to file discovery and reading, and there are no network operation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:49 PM
Security Audit — agent-trust-hub — sbom-analysis