dependency-management
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill instructions and associated workflows follow security best practices, such as utilizing GitHub Secrets for authentication tokens and recommending version pinning for external dependencies.- [EXTERNAL_DOWNLOADS]: The skill references several external GitHub Actions for security auditing and automation, including
aquasecurity/trivy-action,snyk/actions,anchore/sbom-action, andactions/dependency-review-action. These are reputable security tools and their use is appropriate for the skill's stated purpose of dependency management and vulnerability scanning.
Audit Metadata