scan-dependencies

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [External Data Transmission]: The skill uses curl to transmit dependency information, such as package names and versions, to the deps.dev API. This is a standard operation for a security auditing tool and targets an official service endpoint associated with the tool's intended function.
  • [Indirect Prompt Injection Surface]: The skill processes external data in the form of dependency lists provided by the user. While this represents a surface for untrusted input, the skill uses these inputs to construct a structured JSON payload for a specific API request rather than executing them as commands.
  • [Audit Limitations]: The skill includes instructions to treat unflagged dependencies as having an unknown risk level. This is a security best practice, acknowledging that the scanner only detects known issues and cannot guarantee absolute security for all packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 11:47 AM
Security Audit — agent-trust-hub — scan-dependencies