dependency-upgrade

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONMETADATA_POISONINGEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Automated security analysis has flagged the file scripts/generate-dependency-upgrades.sh as containing a backdoor (identified as FileRepMalware [Bd]). This indicates the presence of malicious code designed to grant unauthorized remote access or execute arbitrary commands on the system.
  • [COMMAND_EXECUTION]: The skill includes and instructs the use of shell scripts and CLI tools in an environment where malicious code has been detected. The execution of scripts/generate-dependency-upgrades.sh poses an immediate threat to system integrity.
  • [METADATA_POISONING]: The skill's metadata and documentation use deceptive framing, claiming to provide 'Secure dependency upgrades with supply chain protection' and 'supply chain attack prevention.' This is a social engineering tactic designed to gain the trust of security-conscious users while delivering a supply chain attack (the backdoor).
  • [EXTERNAL_DOWNLOADS]: The skill references the execution of remote scripts, such as using jscodeshift to run a transformation directly from a GitHub URL (https://raw.githubusercontent.com/ReactTraining/react-router/main/packages/react-router/codemods/5.x-6.x.ts). While targeting a known repository, remote script execution is a high-risk pattern that bypasses local security audits.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 12:00 AM
Security Audit — agent-trust-hub — dependency-upgrade