iac-scan-checkov

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill correctly implements instructions for a standard security auditing workflow.\n- [EXTERNAL_DOWNLOADS]: Recommends the installation of Checkov using pip. Checkov is a standard, well-known utility for infrastructure security scanning.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external IaC files through Checkov's output. While this presents a surface for instructions embedded in data, the risk is minimal due to the tool's structured JSON output and the specific reporting requirements.\n
  • Ingestion points: checkov-results.json (SKILL.md)\n
  • Boundary markers: None explicitly defined in instructions, though structured JSON output provides inherent separation.\n
  • Capability inventory: Execution of the checkov CLI tool (SKILL.md)\n
  • Sanitization: None explicitly required for the structured JSON parsing step.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 06:47 PM
Security Audit — agent-trust-hub — iac-scan-checkov