license-compliance-scan

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes project manifest files (e.g., package.json, requirements.txt) which may contain instructions from third-party dependency authors (Indirect Prompt Injection). This is an inherent risk factor for the skill's primary function.
  • Ingestion points: project manifests (package.json, requirements.txt, go.mod, Cargo.toml, Gemfile, pom.xml) and LICENSE files identified in SKILL.md.
  • Boundary markers: None specified to delineate file content from instructions.
  • Capability inventory: The agent reads local project files to identify dependency metadata.
  • Sanitization: No explicit filtering or escaping of content within the read manifest files is described.
  • [SAFE]: The skill includes a reference to the developer's official website (qualitymax.io). This is a standard vendor resource and does not involve executable code or sensitive data transfer.
  • [NO_CODE]: The skill contains only informational markdown instructions and does not ship with any scripts, binaries, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:07 PM
Security Audit — agent-trust-hub — license-compliance-scan