update-dependencies
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted external data to make decisions.
- Ingestion points: Release notes fetched via
gh apiand migration guides found through web searches are fed into the agent's context (SKILL.md). - Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the fetched release notes.
- Capability inventory: The agent possesses significant capabilities, including filesystem modification (fixing code, updating
package.json) and command execution (npm,pnpm,yarn,gh,ctx7). - Sanitization: There is no evidence of filtering or sanitization of the external content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill relies on several command-line tools to perform its tasks.
- It uses standard package managers (
pnpm,npm,yarn) to query and update project dependencies. - It utilizes the GitHub CLI (
gh) to fetch repository metadata and release notes. - The instructions reference an unknown or non-standard CLI tool named
ctx7for accessing migration guides and API documentation.
Audit Metadata