dependency-upgrade
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of high-level procedural instructions for software maintenance. No malicious code, obfuscation, or unauthorized data access patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading project manifest files and external release notes, which are untrusted data sources. However, the instructions emphasize manual verification and behavioral testing, which are effective mitigations against unexpected changes.
- Ingestion points: Project manifest files (e.g.,
package.json,requirements.txt) and external library changelogs/release notes. - Boundary markers: Absent.
- Capability inventory: Use of package managers and test runners.
- Sanitization: Absent; the skill relies on manual review and testing to identify issues.
Audit Metadata