stack-modernization

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git and bun to manage repository state and project dependencies. These operations are restricted to the local workspace and are appropriate for the tool's intended purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes external data (source code and package.json files). However, it implements a structured modernization workflow that includes verification steps and incremental testing to minimize risks.
  • [EXTERNAL_DOWNLOADS]: It fetches package metadata using WebSearch to confirm current versions from npm or GitHub. These are well-known, trusted sources for package management information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:05 PM
Security Audit — agent-trust-hub — stack-modernization