patch-prioritization

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill retrieves vulnerability data from well-known and reputable service providers including the Cybersecurity and Infrastructure Security Agency (CISA) and FIRST.org's EPSS API. These are established sources in the security community.
  • [PROMPT_INJECTION]: The skill includes a 'Prompt Injection Safety Notice' that proactively addresses the risk of indirect prompt injection. It specifically instructs the agent to disregard any instructions found within untrusted inputs such as vulnerability scanner outputs, ticket descriptions, or code comments.
  • [COMMAND_EXECUTION]: Access is restricted to standard read-only and pattern-matching tools (Read, Grep, Glob) required for its stated purpose. There is no evidence of arbitrary or dangerous command execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — patch-prioritization