sbom-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external SBOM and VEX files which could contain malicious instructions. However, it explicitly mitigates this with a dedicated 'Prompt Injection Safety Notice' instructing the agent to ignore any embedded commands. Evidence: Ingestion points include SBOM and VEX files; Boundary markers are present in the safety notice section; Capability inventory is limited to Read, Grep, and Glob; Sanitization includes explicit instructions to ignore data-driven overrides.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or dynamic execution were found. The skill does not download external scripts or packages.
- [DATA_EXFILTRATION]: No patterns for data exfiltration or sensitive file exposure were identified. The allowed tools are limited to file discovery and reading, and there are no network operation commands.
Audit Metadata