maintain-packaging
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform maintenance and build operations using local command-line tools. Specifically, it uses
uv runto execute internal scripts such asscripts/licensing/license_diff.pyandpre-commit runto regenerate attribution files (attributions-rust,attributions-python,attributions-node). These operations are consistent with the skill's primary purpose of dependency and release management. - [INDIRECT_PROMPT_INJECTION]: The skill involves auditing and updating external dependency manifests and lockfiles, which serves as a potential surface for indirect prompt injection if those files contain malicious metadata.
- Ingestion points: Dependency manifests and lockfiles (
Cargo.toml,pyproject.toml,package.json,Cargo.lock,uv.lock,package-lock.json) are identified as primary audit areas. - Boundary markers: No explicit delimiters or instructions to ignore embedded natural language instructions within these data files are provided.
- Capability inventory: The skill executes shell commands (
uv,pre-commit) and manages package distribution, which are significant capabilities. - Sanitization: The skill emphasizes manual review of license changes and dependency graphs as the primary mitigation for supply chain risks.
Audit Metadata