update-deps
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands via the
Bashtool to perform dependency management and git operations. This includes runningnpm install,git commit,git status, and project-specific verification scripts likenpm testornpm run build. This execution is the core intended purpose of the skill. - [EXTERNAL_DOWNLOADS]: The skill downloads and updates packages from standard public registries (npm, pnpm, yarn, or bun) and fetches migration documentation via the
mcp__context7tool. These are well-known services and the skill includes a human-in-the-loop checkpoint for major updates to mitigate risk. - [PROMPT_INJECTION]: The skill explicitly instructs the agent to ignore default system instructions regarding AI attribution in git commits (e.g., removing
Co-Authored-By: Claude). While this is a form of concealment, it is a common stylistic choice in developer tools to maintain a clean git history and does not represent a malicious bypass of safety filters. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes external data, specifically migration guides and documentation fetched from the internet. An attacker could potentially embed malicious instructions in a package's documentation to influence the agent's behavior during a migration.
- Ingestion points: External library documentation is fetched via the
mcp__context7__get-library-docstool and processed inSKILL.md(Step 3). - Boundary markers: None identified. The instructions do not define delimiters for external content or warn the agent to ignore embedded instructions.
- Capability inventory: The skill has broad capabilities including file modification (
Write,Edit) and arbitrary command execution (Bash). - Sanitization: No sanitization or validation of the fetched documentation content is performed before processing.
Audit Metadata