supply-chain-risk-auditor

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool and the GitHub CLI (gh) to perform its audit functions. It executes shell commands to retrieve metadata such as star counts, issue activity, and maintainer information. It also manages a local workspace directory (.supply-chain-risk-auditor) and report files via shell operations.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted dependency data from project files. Ingestion points: Dependency names and repository URLs are extracted from local files using Glob and Grep. Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the processed data. Capability inventory: The skill uses Bash, Write, and the gh CLI to process data and generate reports. Sanitization: No explicit sanitization or validation logic is defined for the strings extracted from project files before they are included in shell commands or final reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — supply-chain-risk-auditor