stack-modernization
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
gitandbunto manage repository state and project dependencies. These operations are restricted to the local workspace and are appropriate for the tool's intended purpose. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes external data (source code and
package.jsonfiles). However, it implements a structured modernization workflow that includes verification steps and incremental testing to minimize risks. - [EXTERNAL_DOWNLOADS]: It fetches package metadata using
WebSearchto confirm current versions from npm or GitHub. These are well-known, trusted sources for package management information.
Audit Metadata