iac-scan-checkov
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill correctly implements instructions for a standard security auditing workflow.\n- [EXTERNAL_DOWNLOADS]: Recommends the installation of Checkov using pip. Checkov is a standard, well-known utility for infrastructure security scanning.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external IaC files through Checkov's output. While this presents a surface for instructions embedded in data, the risk is minimal due to the tool's structured JSON output and the specific reporting requirements.\n
- Ingestion points: checkov-results.json (SKILL.md)\n
- Boundary markers: None explicitly defined in instructions, though structured JSON output provides inherent separation.\n
- Capability inventory: Execution of the checkov CLI tool (SKILL.md)\n
- Sanitization: None explicitly required for the structured JSON parsing step.
Audit Metadata