dependency-audit

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configures CI workflows using well-known and trusted GitHub Actions from established providers, including official actions from GitHub, Oven, and Gitleaks.
  • [DATA_EXFILTRATION]: Implements logic to scan for credentials in the working tree but correctly incorporates safeguards by instructing the agent to never reproduce secret values in reports, recommending rotation instead.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from lockfiles and dependency manifests. This creates an indirect prompt injection surface where malicious metadata in a third-party package could attempt to influence agent behavior. While the instructions include a warning to treat quoted code as untrusted, the ingestion surface remains present.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 02:10 AM
Security Audit — agent-trust-hub — dependency-audit