dependabot
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation and reference materials providing guidance on GitHub Dependabot configuration.
- [SAFE]: No executable scripts, shell commands, or dynamic context injection patterns (such as
!command) were found in any of the files. - [SAFE]: The documentation follows security best practices for credential management, recommending the use of GitHub Secrets placeholders (e.g.,
${{secrets.NPM_TOKEN}}) rather than hardcoded secrets. - [SAFE]: All ecosystem and registry references are standard for the tool being documented and point to well-known services or example domains.
Audit Metadata