update-dependencies

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted external data to make decisions.
  • Ingestion points: Release notes fetched via gh api and migration guides found through web searches are fed into the agent's context (SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the fetched release notes.
  • Capability inventory: The agent possesses significant capabilities, including filesystem modification (fixing code, updating package.json) and command execution (npm, pnpm, yarn, gh, ctx7).
  • Sanitization: There is no evidence of filtering or sanitization of the external content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill relies on several command-line tools to perform its tasks.
  • It uses standard package managers (pnpm, npm, yarn) to query and update project dependencies.
  • It utilizes the GitHub CLI (gh) to fetch repository metadata and release notes.
  • The instructions reference an unknown or non-standard CLI tool named ctx7 for accessing migration guides and API documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:02 AM
Security Audit — agent-trust-hub — update-dependencies