scan-dependencies
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [External Data Transmission]: The skill uses
curlto transmit dependency information, such as package names and versions, to thedeps.devAPI. This is a standard operation for a security auditing tool and targets an official service endpoint associated with the tool's intended function. - [Indirect Prompt Injection Surface]: The skill processes external data in the form of dependency lists provided by the user. While this represents a surface for untrusted input, the skill uses these inputs to construct a structured JSON payload for a specific API request rather than executing them as commands.
- [Audit Limitations]: The skill includes instructions to treat unflagged dependencies as having an unknown risk level. This is a security best practice, acknowledging that the scanner only detects known issues and cannot guarantee absolute security for all packages.
Audit Metadata