dependency-tracker

Fail

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The utils.py utility script includes a get_github_token function that reads the ~/.git-credentials file. This is performed to extract authentication tokens for use in requests to the GitHub API, which is a standard procedure for increasing API rate limits but involves accessing sensitive credential files.
  • [COMMAND_EXECUTION]: The scan.py script executes multiple system-level shell commands via subprocess.run, including npm outdated, pip3 list --outdated, git hash-object, and openclaw --version. These operations are fundamental to the skill's purpose of inventorying local dependencies and their versions.
  • [EXTERNAL_DOWNLOADS]: The check.py script performs network requests to api.github.com, registry.npmjs.org, and clawhub.ai to retrieve remote version data and metadata. It also downloads the content of remote SKILL.md files from GitHub to perform local/remote diffing.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data when downloading and processing remote SKILL.md files for its reporting functionality.
  • Ingestion points: Remote SKILL.md content fetched via GitHub's download_url in scripts/check.py.
  • Boundary markers: None identified; the skill incorporates remote content samples directly into the generated Markdown report without specialized delimiters.
  • Capability inventory: The skill possesses file system write access (to the data/ directory) and shell command execution capabilities (subprocess.run).
  • Sanitization: The skill uses a redact_path function in scripts/utils.py to mask absolute local paths in generated reports, protecting system structure information.
Recommendations
  • HIGH: Downloads and executes remote code from: unknown (check file) - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 9, 2026, 01:43 PM