dependency-management

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party data from multiple sources, which could potentially contain malicious instructions. 1. Ingestion points: The skill reads package manifests (package.json, requirements.txt) and parses output from audit tools like npm audit, pip-audit, and Socket.dev. 2. Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish package metadata from executable instructions. 3. Capability inventory: The skill has access to Bash for running audits and file system Write/Edit permissions for configuration management. 4. Sanitization: No explicit sanitization or validation logic for the external data is described.
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions in references/security-auditing.md to install the Grype security scanner by fetching a shell script from the official Anchore GitHub repository and piping it directly into the shell (curl ... | sh). While the source is a well-known security vendor, the method of execution is a high-risk pattern.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of various security auditing tools and libraries, including snyk, socket, and pip-audit, from public package registries and external repositories.
  • [COMMAND_EXECUTION]: The skill relies on numerous shell commands to perform dependency analysis, license compliance checks, and SBOM generation across Node.js, Python, Rust, and Go environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — dependency-management