sec-dependency-audit
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely instructional, providing a framework for identifying and remediating supply chain vulnerabilities. It promotes security best practices, such as using lockfiles, pinning commit SHAs in GitHub Actions, and utilizing established auditing tools like npm audit, pip-audit, and Trivy.
- [NO_CODE]: There are no scripts, executables, or automated tool configurations included in this skill. All actions described are intended to be performed by a human user or guided by the AI through conversation.
Audit Metadata