dependency-management-deps-audit
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches vulnerability advisories and package metadata from established and well-known services including the NPM Registry, PyPI, RubyGems, and Sonatype OSS Index.
- [COMMAND_EXECUTION]: Provides automated remediation templates that utilize standard package management CLI tools such as
npm,pip, andpip-compileto apply security updates. - [EXTERNAL_DOWNLOADS]: References BundlePhobia to perform bundle size analysis, which is a common practice for evaluating dependency impact.
- [DATA_EXFILTRATION]: Reads local dependency manifest files (e.g.,
package.json,requirements.txt) to extract package names and versions for security lookup; this behavior is transparent and essential to the skill's stated purpose.
Audit Metadata