dep-verify-guard

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute package manager CLI commands such as npm view, pip index, and cargo search. These are used for querying official registries to verify package metadata.
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the use of official registry APIs (e.g., npmjs.org, pypi.org, crates.io) and related services like pypistats.org. These well-known services are accessed via standard network operations to fetch metadata for verification purposes.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is designed to ingest and process untrusted manifest files such as package.json, requirements.txt, and Cargo.toml.
  • Ingestion points: Reads dependency lists from developer-supplied manifest and lock files.
  • Boundary markers: The instructions do not specify explicit delimiters for the data but treat all findings as untrusted until external verification is complete.
  • Capability inventory: Uses shell command execution and network browsing/fetching capabilities.
  • Sanitization: The skill relies on the package manager's own CLI and API parsing logic; no additional sanitization of input package names is described in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 10:36 AM
Security Audit — agent-trust-hub — dep-verify-guard