dependency-scan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of established security auditing tools for various programming ecosystems, including Node.js, Python, Ruby, Java, Go, Rust, PHP, and .NET. This command execution is essential for its primary function of scanning and optionally fixing vulnerable packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection as it ingests and parses external dependency manifest files.
  • Ingestion points: Manifest files such as package.json, requirements.txt, Gemfile, pom.xml, go.mod, and Cargo.toml found in the target project.
  • Boundary markers: The instructions do not specify explicit delimiters or warnings for the agent to disregard potential instructions embedded within the package manifests.
  • Capability inventory: The skill has the capability to execute shell commands (for auditing) and write to the local filesystem (when using the --fix flag to update dependencies).
  • Sanitization: There are no documented sanitization steps or validation schemas for the manifest data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:47 PM
Security Audit — agent-trust-hub — dependency-scan