dependency-tracker
Fail
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
utils.pyutility script includes aget_github_tokenfunction that reads the~/.git-credentialsfile. This is performed to extract authentication tokens for use in requests to the GitHub API, which is a standard procedure for increasing API rate limits but involves accessing sensitive credential files. - [COMMAND_EXECUTION]: The
scan.pyscript executes multiple system-level shell commands viasubprocess.run, includingnpm outdated,pip3 list --outdated,git hash-object, andopenclaw --version. These operations are fundamental to the skill's purpose of inventorying local dependencies and their versions. - [EXTERNAL_DOWNLOADS]: The
check.pyscript performs network requests toapi.github.com,registry.npmjs.org, andclawhub.aito retrieve remote version data and metadata. It also downloads the content of remoteSKILL.mdfiles from GitHub to perform local/remote diffing. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data when downloading and processing remote
SKILL.mdfiles for its reporting functionality. - Ingestion points: Remote
SKILL.mdcontent fetched via GitHub'sdownload_urlinscripts/check.py. - Boundary markers: None identified; the skill incorporates remote content samples directly into the generated Markdown report without specialized delimiters.
- Capability inventory: The skill possesses file system write access (to the
data/directory) and shell command execution capabilities (subprocess.run). - Sanitization: The skill uses a
redact_pathfunction inscripts/utils.pyto mask absolute local paths in generated reports, protecting system structure information.
Recommendations
- HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata