supply-chain-risk-auditor
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purpose-built for security auditing of third-party dependencies, focusing on maintainer posture and supply-chain integrity.
- [SAFE]: Command execution is limited to standard diagnostic tools like
git,grep, andsortused on the local repository metadata to analyze maintainer history. - [SAFE]: External network access via
WebFetchorcurlis directed towards well-known and trusted services such as GitHub and npm for retrieving public package metadata. - [SAFE]: No evidence of prompt injection, obfuscation, or unauthorized data access was found in the skill instructions or methodology.
Audit Metadata