dependency-upgrade
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONMETADATA_POISONINGEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: Automated security analysis has flagged the file
scripts/generate-dependency-upgrades.shas containing a backdoor (identified as FileRepMalware [Bd]). This indicates the presence of malicious code designed to grant unauthorized remote access or execute arbitrary commands on the system. - [COMMAND_EXECUTION]: The skill includes and instructs the use of shell scripts and CLI tools in an environment where malicious code has been detected. The execution of
scripts/generate-dependency-upgrades.shposes an immediate threat to system integrity. - [METADATA_POISONING]: The skill's metadata and documentation use deceptive framing, claiming to provide 'Secure dependency upgrades with supply chain protection' and 'supply chain attack prevention.' This is a social engineering tactic designed to gain the trust of security-conscious users while delivering a supply chain attack (the backdoor).
- [EXTERNAL_DOWNLOADS]: The skill references the execution of remote scripts, such as using
jscodeshiftto run a transformation directly from a GitHub URL (https://raw.githubusercontent.com/ReactTraining/react-router/main/packages/react-router/codemods/5.x-6.x.ts). While targeting a known repository, remote script execution is a high-risk pattern that bypasses local security audits.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata