dependency-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides Python scripts (dep_scanner.py, license_checker.py, upgrade_planner.py) designed for CLI execution. These scripts perform targeted file system traversal and read operations on project manifest files to extract dependency information. This behavior is necessary for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from project manifests (e.g., package.json, requirements.txt) to generate reports. While this presents an attack surface where a malicious manifest could influence the agent's analysis, the risk is mitigated by the tool's specialized focus and structured output.
  • Ingestion points: Manifest files located within the user-specified project path.
  • Boundary markers: The scripts generate structured text or JSON reports with clear headers and delimiters.
  • Capability inventory: The tool has file system read access and CLI execution capabilities; it does not perform network operations in the provided code.
  • Sanitization: Dependency names and versions are extracted using specific regular expression patterns to ensure only relevant metadata is processed.
  • [EXTERNAL_DOWNLOADS]: The documentation mentions the ability to fetch data from external registries and custom databases. However, the analyzed scripts currently rely on built-in hardcoded data and simulated (mocked) registry checks, ensuring all operations remain local and verifiable.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:33 PM