dependency-updater

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill runs ecosystem-specific command-line tools (such as taze, pip, go, cargo, bundle, mvn, and dotnet) to check for updates and audit security vulnerabilities. This command execution is aligned with the primary purpose of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection risk surface because it parses untrusted configuration files from a workspace.
  • Ingestion points: Local workspace files including package.json, requirements.txt, go.mod, Cargo.toml, and other package definition manifests.
  • Boundary markers: Absent; there are no explicit instructions or delimiters telling the agent to ignore natural language instructions embedded within package fields.
  • Capability inventory: Executes shell scripts (scripts/check-tool.sh and scripts/run-taze.sh) along with system package managers.
  • Sanitization: Absent; the skill relies entirely on standard tools and does not preprocess or sanitize incoming file data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:53 AM