dependency-check
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npx @claude-flow/cli@latestto dynamically fetch and execute an unversioned package from the npm registry at runtime, introducing a risk of supply chain contamination if the third-party package is compromised or altered. - [COMMAND_EXECUTION]: The skill executes system shell commands using
npxandnpm auditto check project dependencies and perform automated operations.
Audit Metadata