policy-risk-scanner
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill is entirely instructional and composed of Markdown documentation. It does not contain any scripts, binaries, or configuration files.
- [COMMAND_EXECUTION]: The documentation references various
npmshell commands intended for automation. These commands are descriptive of the tool's intended workflow and do not constitute malicious command execution. - [PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external, untrusted content from URLs. This creates a surface for indirect prompt injection, where an attacker could place instructions on a website to influence the agent's behavior during a scan. This risk is inherent to the skill's purpose.
Audit Metadata