dependency-audit

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or behaviors were detected. The skill serves as an instructional guide and reporting template.
  • [COMMAND_EXECUTION]: Includes standard shell commands for package managers (npm, pip, go, maven) and security auditing tools provided as recommendations for remediation plans.
  • [EXTERNAL_DOWNLOADS]: Recommends using security scanning tools from trusted organizations, such as Google's official license checker and official ecosystem vulnerability tools.
  • [PROMPT_INJECTION]: The skill analyzes untrusted dependency manifests (e.g., package.json), which presents an indirect prompt injection surface where malicious metadata could be embedded in the analyzed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:10 AM
Security Audit — agent-trust-hub — dependency-audit