detecting-typosquatting-packages
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides procedures to download established security tools and datasets from GitHub repositories, including Microsoft's OSSGadget and the Rust Foundation's typomania.
- [COMMAND_EXECUTION]: The workflow documentation includes standard installation and build commands, such as cargo build and pip install, to prepare the environment for dependency screening.
- [DATA_EXFILTRATION]: The included Python script and described methodologies communicate with official package registry APIs at registry.npmjs.org and pypi.org to retrieve package metadata and download statistics for legitimate auditing purposes.
Audit Metadata