dependency-audit
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes native ecosystem tools (such as
npm audit,pip-audit, andcargo audit) to perform security assessments of the project dependencies. - [EXTERNAL_DOWNLOADS]: Fetches security advisory feeds and API data from well-known services, including the npm registry and the RustSec advisory database, to provide fallback scanning capabilities.
- [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. Network activity is exclusively focused on retrieving security metadata from established tech company repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project manifest files and CLI tool outputs. This constitutes an indirect prompt injection surface common to all file-processing tools, though the risk is mitigated by the skill's read-only reporting architecture.
Audit Metadata