secure-dependencies
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository configuration files (such as package.json and lockfiles) which are potentially attacker-controlled inputs if the agent is used on untrusted repositories.
- Ingestion points: Processes package.json and lockfiles within the repository during audit and review workflows (SKILL.md).
- Boundary markers: No specific delimiters or 'ignore embedded instructions' warnings are defined for the repository content being reviewed.
- Capability inventory: Uses suggest-shell to recommend commands to the user (SKILL.md).
- Sanitization: No explicit sanitization or validation of package names or version strings before they are incorporated into generated documentation or policy suggestions.
- [EXTERNAL_DOWNLOADS]: The skill includes references to the author's official repositories and packages.
- Evidence: Links to the bh611627/skillcodex GitHub repository and the @skillcodex/skills npm package.
Audit Metadata