bom-generator
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows best practices for local script execution. It uses the
uvtool to manage theopenpyxldependency through a standard PEP 723 metadata block. The Python script (scripts/generate_bom.py) performs routine data processing and file operations (writing .xlsx, .csv, and .md files) based on user input or local JSON files. No network exfiltration, obfuscation, or unauthorized access to sensitive files was found. External links provided in the component database and examples point to well-known and legitimate electronics suppliers.
Audit Metadata