supply-chain-risk-auditor

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purpose-built for security auditing of third-party dependencies, focusing on maintainer posture and supply-chain integrity.
  • [SAFE]: Command execution is limited to standard diagnostic tools like git, grep, and sort used on the local repository metadata to analyze maintainer history.
  • [SAFE]: External network access via WebFetch or curl is directed towards well-known and trusted services such as GitHub and npm for retrieving public package metadata.
  • [SAFE]: No evidence of prompt injection, obfuscation, or unauthorized data access was found in the skill instructions or methodology.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:14 AM
Security Audit — agent-trust-hub — supply-chain-risk-auditor