skills/data-fair/lib/deps-refresh/Gen Agent Trust Hub

deps-refresh

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses various command-line tools for auditing and testing, including npm audit, npm outdated, docker build/run, trivy, and npx playwright. These are standard utilities for dependency management and security scanning.
  • [EXTERNAL_DOWNLOADS]: The skill fetches updates from official registries (npm, Alpine apk) and container images from the vendor's GitHub Container Registry (ghcr.io/data-fair/). These interactions are limited to standard package management and deployment workflows.
  • [DYNAMIC_EXECUTION]: The verification phase uses node -e to execute a small script fragment within a container to test module loading and configuration. This is a common smoke-testing technique to ensure the runtime environment is correctly configured.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:49 PM
Security Audit — agent-trust-hub — deps-refresh