plan-dependency-provenance
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is inherently defensive and aims to prevent supply-chain attacks. It provides specific instructions to verify the existence and integrity of dependencies against official registries without installing them.\n- [SAFE]: Contains strong procedural guardrails that enforce a 'plan-only' mode, explicitly forbidding commands like
npm installorpip installduring the audit phase to prevent accidental execution of malicious code.\n- [SAFE]: The skill addresses Indirect Prompt Injection risks by establishing clear boundary markers, such as the 'Plan only' guardrail and a phased approval process for any proposed changes to dependency manifests.
Audit Metadata