deps-refresh
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses various command-line tools for auditing and testing, including
npm audit,npm outdated,docker build/run,trivy, andnpx playwright. These are standard utilities for dependency management and security scanning. - [EXTERNAL_DOWNLOADS]: The skill fetches updates from official registries (npm, Alpine apk) and container images from the vendor's GitHub Container Registry (
ghcr.io/data-fair/). These interactions are limited to standard package management and deployment workflows. - [DYNAMIC_EXECUTION]: The verification phase uses
node -eto execute a small script fragment within a container to test module loading and configuration. This is a common smoke-testing technique to ensure the runtime environment is correctly configured.
Audit Metadata