dependency-updater
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill runs ecosystem-specific command-line tools (such as
taze,pip,go,cargo,bundle,mvn, anddotnet) to check for updates and audit security vulnerabilities. This command execution is aligned with the primary purpose of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection risk surface because it parses untrusted configuration files from a workspace.
- Ingestion points: Local workspace files including
package.json,requirements.txt,go.mod,Cargo.toml, and other package definition manifests. - Boundary markers: Absent; there are no explicit instructions or delimiters telling the agent to ignore natural language instructions embedded within package fields.
- Capability inventory: Executes shell scripts (
scripts/check-tool.shandscripts/run-taze.sh) along with system package managers. - Sanitization: Absent; the skill relies entirely on standard tools and does not preprocess or sanitize incoming file data.
Audit Metadata