live-dependency-resolver

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Instructs the agent to use local CLI tools (npm, pip, go, cargo, gem) to query package metadata, which is the preferred method for performance and local cache usage.
  • [EXTERNAL_DOWNLOADS]: Provides fallback instructions to fetch package information directly from official, well-known registry APIs (e.g., registry.npmjs.org, pypi.org, crates.io) using curl when CLI tools are missing.
  • [PROMPT_INJECTION]: Contains a cosmetic instruction for the agent to prefix responses with a specific emoji (๐Ÿงข) and a behavioral instruction to perform a discovery check for related companion skills within the agent's installation directories on first use. This discovery mechanism facilitates the installation of complementary tools from the same vendor.
  • [DATA_EXFILTRATION]: No sensitive data access or exfiltration patterns were detected. The network operations are scoped strictly to official package registry APIs for metadata retrieval.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit โ€” agent-trust-hub โ€” live-dependency-resolver