dependency-upgrade

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is primarily instructional and provides templates for secure project configuration. It promotes defense-in-depth strategies such as disabling post-install scripts and enforcing deterministic installations in CI environments.
  • [SAFE]: The provided automation script (scripts/generate-dependency-upgrades.sh) is a benign utility for copying configuration templates and does not perform network operations or execute untrusted code.
  • [EXTERNAL_DOWNLOADS]: The skill references and recommends several established security tools and services, including Socket CLI, Snyk, and npq, to audit and protect the dependency tree.
  • [REMOTE_CODE_EXECUTION]: Includes instructions for running official codemods from trusted sources, such as the React Router GitHub repository, using jscodeshift. These references are documented neutrally as they originate from well-known community organizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 09:31 AM
Security Audit — agent-trust-hub — dependency-upgrade