skills/trailofbits/skills/ossfuzz/Gen Agent Trust Hub

ossfuzz

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the official OSS-Fuzz infrastructure from Google's public GitHub repository.
  • [COMMAND_EXECUTION]: Instructs the agent to execute shell commands for cloning repositories, building Docker images, and running fuzzing harnesses using the uv and docker CLI tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on external data by cloning the OSS-Fuzz repository and processing project-specific files (e.g., project.yaml, Dockerfile, build.sh). While this creates an ingestion surface for third-party content, the primary sources are well-known and reputable services. The skill lacks explicit boundary markers for data processed during these steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:16 PM
Security Audit — agent-trust-hub — ossfuzz