audit-dependencies

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via project manifest files.\n
  • Ingestion points: The skill reads project manifests like package.json, pyproject.toml, go.mod, Gemfile, Cargo.toml, and composer.json to extract dependency lists.\n
  • Boundary markers: There are no instructions or delimiters provided to the agent to treat manifest data as untrusted or to ignore instructions embedded in package names.\n
  • Capability inventory: The skill requires the agent to execute shell commands, including grep, npm audit, and pip-audit, providing a mechanism for command execution.\n
  • Sanitization: The grep command in Step 5 interpolates the package name (${PKG}) directly into a shell command string. An attacker-controlled package name could use shell metacharacters (e.g., ;, &&, |) to execute arbitrary commands if the agent does not perform its own sanitization.\n
  • Mitigation: The skill should explicitly instruct the agent to sanitize all package names before use in shell commands, use structured data tools where possible, and wrap external content in clear delimiters with instructions to ignore embedded commands.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute various ecosystem-specific audit and version tools based on manifest file contents.\n
  • Evidence: Steps 2, 3, and 5 specify shell commands such as npm audit, pip-audit, govulncheck, bundle audit, cargo audit, and a custom grep command.\n
  • Risk: The construction of these commands relies on untrusted input from manifest files, creating a security risk if those files are malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:13 AM
Security Audit — agent-trust-hub — audit-dependencies