sbom-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust security model for processing untrusted external data. It specifically includes a 'Prompt Injection Safety Notice' that instructs the agent to ignore any instructions or overrides found within SBOM or VEX metadata. Execution is limited to local file system operations with no network access enabled, preventing data exfiltration or remote code execution. All referenced frameworks and URLs point to well-known, official industry standards and government resources.
Audit Metadata