dependency-audit

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes native ecosystem tools (such as npm audit, pip-audit, and cargo audit) to perform security assessments of the project dependencies.
  • [EXTERNAL_DOWNLOADS]: Fetches security advisory feeds and API data from well-known services, including the npm registry and the RustSec advisory database, to provide fallback scanning capabilities.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. Network activity is exclusively focused on retrieving security metadata from established tech company repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project manifest files and CLI tool outputs. This constitutes an indirect prompt injection surface common to all file-processing tools, though the risk is mitigated by the skill's read-only reporting architecture.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:23 AM
Security Audit — agent-trust-hub — dependency-audit