sca-pip-audit
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Recommends installing 'pip-audit', a well-known Python security utility, via 'pip install'.
- [COMMAND_EXECUTION]: Instructions include running shell commands for vulnerability scanning and package remediation.
- [INDIRECT_PROMPT_INJECTION]: The skill reads and summarizes vulnerability information from the OSV and PyPI databases.
- Ingestion points: External vulnerability data in 'pip-audit-results.json' (SKILL.md).
- Boundary markers: Absent; results are parsed directly into Markdown tables.
- Capability inventory: Shell execution of security tools and package managers (pip).
- Sanitization: None; data is presented for user review.
Audit Metadata