dependency-security-audit

Warn

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions define specific search patterns and heuristics to locate sensitive authentication material, including AWS access keys, GitHub personal access tokens, Slack tokens, and JWTs. It explicitly targets files known to contain secrets, such as .env, .pem, and credentials files.
  • [COMMAND_EXECUTION]: The skill requires the execution of various ecosystem-specific CLI tools to perform its audit functions. These include npm audit, pnpm audit, yarn audit, mvn dependency:tree, gradle dependencies, pip-audit, and osv-scanner. The skill relies on these external binaries being present in the execution environment.
  • [DATA_EXFILTRATION]: The skill performs automated discovery and exposure of sensitive file paths across the repository, including private keys and configuration files. Although the instructions advise the agent to only report the location and not the value of discovered secrets, the process involves programmatic access to and evaluation of sensitive credential data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 12, 2026, 05:26 PM
Security Audit — agent-trust-hub — dependency-security-audit