upgrade-dependencies
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands via the project's package manager (npm, pnpm, yarn, or bun) to install dependencies and run project-defined scripts found in
package.json(e.g., build, test, lint, and typecheck commands). - [EXTERNAL_DOWNLOADS]: The skill fetches package metadata and version information from the npm registry using
npm viewcommands. It also instructs the agent to consult GitHub releases and issue trackers to triage dependency incompatibilities. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted external data during its workflow.
- Ingestion points: Reads output from
npm view, captures logs from failing build/test scripts, and reads content from external GitHub issues and pull requests. - Boundary markers: The instructions do not define specific delimiters or 'ignore' instructions for the data being processed.
- Capability inventory: The skill has the ability to write to the local filesystem (
package.json, source code fixes) and execute arbitrary shell commands defined in the project's environment. - Sanitization: There is no mention of sanitization or filtering for the external content retrieved from registries or issue trackers.
Audit Metadata