supply-chain-hardening

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a defensive resource that provides reasoning for securing package management across multiple ecosystems including npm, pnpm, bun, Python, and Rust. It identifies common attack vectors such as install-time scripts and load-time triggers. \n- [SAFE]: The skill includes a fixture with a known malicious package (@ctrl/tinycolor@4.1.1) in evals/fixtures/compromised-lockfile/package-lock.json. This version is associated with a real malware advisory (Shai-Hulud worm). The content is intended for grading the agent's response to security incidents and is accompanied by explicit warnings not to install or execute it. \n- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by processing untrusted data from package manifests and lockfiles. Ingestion points: package-lock.json and ci-output.txt in the evaluation fixtures. Boundary markers: Explicit warnings are present in SKILL.md and README.md to prevent accidental execution of the fixture data. Capability inventory: The skill provides reasoning guidelines but does not implement automated tool execution, network operations, or file system modifications. Sanitization: Relies on human-in-the-loop decision-making and explicit allowlisting configurations as described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 04:51 PM
Security Audit — agent-trust-hub — supply-chain-hardening