ossfuzz
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the official OSS-Fuzz infrastructure from Google's public GitHub repository.
- [COMMAND_EXECUTION]: Instructs the agent to execute shell commands for cloning repositories, building Docker images, and running fuzzing harnesses using the
uvanddockerCLI tools. - [INDIRECT_PROMPT_INJECTION]: The skill operates on external data by cloning the OSS-Fuzz repository and processing project-specific files (e.g.,
project.yaml,Dockerfile,build.sh). While this creates an ingestion surface for third-party content, the primary sources are well-known and reputable services. The skill lacks explicit boundary markers for data processed during these steps.
Audit Metadata