dependency-audit
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or behaviors were detected. The skill serves as an instructional guide and reporting template.
- [COMMAND_EXECUTION]: Includes standard shell commands for package managers (npm, pip, go, maven) and security auditing tools provided as recommendations for remediation plans.
- [EXTERNAL_DOWNLOADS]: Recommends using security scanning tools from trusted organizations, such as Google's official license checker and official ecosystem vulnerability tools.
- [PROMPT_INJECTION]: The skill analyzes untrusted dependency manifests (e.g., package.json), which presents an indirect prompt injection surface where malicious metadata could be embedded in the analyzed data.
Audit Metadata