auditing-supply-chain
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation and instructional resource for performing security audits and does not execute malicious code or contain hidden prompt injections.
- [EXTERNAL_DOWNLOADS]: The skill describes using
https://defuddle.md/to fetch and convert external web pages into markdown. This is documented as a utility for token-efficient data ingestion by the agent, and the skill includes explicit warnings regarding the privacy and operational security risks of routing sensitive URLs through third-party services. - [COMMAND_EXECUTION]: Provides numerous examples of shell commands for security tools such as
osv-scanner,trivy,grype,gitleaks, andcheckov. These commands are standard for the stated purpose of auditing supply chain risk. - [PROMPT_INJECTION]: The skill identifies a potential indirect prompt injection surface through the ingestion of external markdown content. The instructions provide explicit guidance on when it is inappropriate to use this ingestion method, such as when dealing with adversary infrastructure or client-owned hosts, effectively mitigating the risk through user/agent awareness.
Audit Metadata