building-vulnerability-scanning-workflow

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Orchestrates network discovery and vulnerability scanning using the python-nmap library, which is the primary intended function of the skill.
  • [EXTERNAL_DOWNLOADS]: Connects to the official CISA website to retrieve the Known Exploited Vulnerabilities (KEV) catalog for risk-based enrichment.
  • [DATA_EXFILTRATION]: Performs authorized network requests to internal security scanners and an external ServiceNow instance for incident management, utilizing configuration placeholders for all credentials.
  • [COMMAND_EXECUTION]: Includes a documented feature to bypass TLS verification (SKIP_TLS_VERIFY) for local development or lab environments, which is a common requirement for internal security tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 10:26 AM