dsh-upgrade-audit

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads npm packages and fetches commit history from the GitHub API. To maintain security, the materialize-npm.mjs script utilizes the --ignore-scripts flag during installation, preventing any malicious lifecycle scripts from executing on the host machine.
  • [COMMAND_EXECUTION]: The skill relies on local git and npm binaries to perform audits, generate diffs, and fetch package metadata. The implementation includes safeguards against command injection, specifically validating that version strings and other arguments do not contain shell metacharacters when running in environments where a shell might be invoked.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, such as git logs and third-party package contents. It is designed to treat these as data sources for a structured report rather than instructions. The skill instructions emphasize re-verifying claims across multiple sources (git diffs and tree reads) to ensure accuracy and mitigate the impact of potentially deceptive narratives in logs.
  • [SAFE]: The skill operates within a restricted directory structure (tmp/) and adheres to a read-only policy for the host project's source code, ensuring that the audit process does not unintentionally modify the user's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 06:18 AM