npm-package-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows secure patterns by using a dedicated tool gateway for accessing external data and specifies a read-only research workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from npm packages (metadata, descriptions) which represents a surface for indirect prompt injection. The risk is mitigated by the skill's restricted read-only capability scope. Ingestion points: Data retrieved via strale_npm_package_info (SKILL.md). Boundary markers: The skill does not explicitly define delimiters for external content. Capability inventory: No high-privilege capabilities; tools are limited to read-only research. Sanitization: No explicit sanitization or filtering of retrieved package data is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — npm-package-research