live-dependency-resolver
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Instructs the agent to use local CLI tools (
npm,pip,go,cargo,gem) to query package metadata, which is the preferred method for performance and local cache usage. - [EXTERNAL_DOWNLOADS]: Provides fallback instructions to fetch package information directly from official, well-known registry APIs (e.g., registry.npmjs.org, pypi.org, crates.io) using
curlwhen CLI tools are missing. - [PROMPT_INJECTION]: Contains a cosmetic instruction for the agent to prefix responses with a specific emoji (๐งข) and a behavioral instruction to perform a discovery check for related companion skills within the agent's installation directories on first use. This discovery mechanism facilitates the installation of complementary tools from the same vendor.
- [DATA_EXFILTRATION]: No sensitive data access or exfiltration patterns were detected. The network operations are scoped strictly to official package registry APIs for metadata retrieval.
Audit Metadata