upgrade-dependencies
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to audit, list, and install software packages via standard managers including npm, yarn, pnpm, pip, poetry, go, and cargo. It also executes verification scripts like 'npm test'. These actions are legitimate and aligned with the skill's primary purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes external data which could theoretically contain malicious instructions designed to influence the agent's behavior. Ingestion points: The agent reads package manifests (e.g., package.json, requirements.txt) and external release notes or changelogs from GitHub. Boundary markers: The instructions do not define delimiters or warnings to ignore instructions embedded in the external text. Capability inventory: The skill has the capability to modify the filesystem and execute commands through package managers and test runners. Sanitization: There is no evidence of content filtering or validation for the data retrieved from external changelogs.
Audit Metadata