plan-dependency-provenance

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a security auditing tool. Its primary purpose is to identify and remediate risks in project dependencies, such as malicious packages or licensing conflicts.
  • [EXTERNAL_DOWNLOADS]: While the skill involves resolving dependency names against public registries (e.g., npm, PyPI), this is the intended and necessary behavior for an audit tool. It does not perform any unauthorized or suspicious external downloads.
  • [COMMAND_EXECUTION]: The skill includes explicit guardrails that forbid the agent from installing or updating packages. It mandates an 'audit-and-plan' only workflow, ensuring no code execution occurs during the verification process.
  • [PROMPT_INJECTION]: No malicious prompt injection patterns were found. The instructional language used ('Senior supply-chain engineer', 'Task:', 'Guardrails:') is consistent with standard AI agent role-definition and does not attempt to bypass safety filters.
  • [DATA_EXFILTRATION]: There is no evidence of commands or instructions designed to access sensitive files or exfiltrate local data to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 11:19 AM
Security Audit — agent-trust-hub — plan-dependency-provenance