dependency-management

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions and associated workflows follow security best practices, such as utilizing GitHub Secrets for authentication tokens and recommending version pinning for external dependencies.- [EXTERNAL_DOWNLOADS]: The skill references several external GitHub Actions for security auditing and automation, including aquasecurity/trivy-action, snyk/actions, anchore/sbom-action, and actions/dependency-review-action. These are reputable security tools and their use is appropriate for the skill's stated purpose of dependency management and vulnerability scanning.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 06:46 AM
Security Audit — agent-trust-hub — dependency-management