skills/johnlindquist/claude/deps/Gen Agent Trust Hub

deps

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install standard utility packages such as yarn, pnpm, and depcheck from the official npm registry.
  • [COMMAND_EXECUTION]: The skill utilizes common command-line tools for dependency management, including npm, yarn, and pnpm, as well as troubleshooting actions like removing lock files (rm package-lock.json).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from package manager outputs which could potentially contain untrusted content from package metadata.
  • Ingestion points: Output from package audit, outdated package checks, and dependency analysis tools in SKILL.md.
  • Boundary markers: None specified; the skill processes standard tool outputs directly.
  • Capability inventory: Ability to install/uninstall packages, write report files, and execute project test scripts as described in SKILL.md.
  • Sanitization: None specified; the skill relies on the integrity of the underlying package management tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — deps