supply-chain-gate

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to improve repository security by providing structured processes for triaging dependency alerts and enforcing supply chain policies.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows security best practices by explicitly instructing users not to commit API tokens and to use GitHub Actions secrets for the SOCKET_SECURITY_API_KEY in references/socket-github-actions.md.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external security alerts (Socket PR comments and dashboard). This attack surface is mitigated by instructions in references/alert-triage.md that mandate mapping all findings against a local policy-allowlist.md and SECURITY.md, which serve as boundary markers for decision-making. The ingestion points are external PR comments and CI logs; capabilities include running audit commands such as npm audit.- [EXTERNAL_DOWNLOADS]: References to external resources in references/socket-github-actions.md point to Socket.dev, which is a well-known security service. These references are informative and facilitate the intended security purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 10:39 PM
Security Audit — agent-trust-hub — supply-chain-gate