supply-chain-security
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is a collection of instructional Markdown documents and does not contain any executable code, scripts, or binaries. It functions as a set of logic-based guidelines for a model to follow when reviewing provided code snippets.
- [SAFE]: Static analysis triggers for obfuscation and base64-to-execution patterns are false positives. The detections were triggered by descriptive text and code block examples used for educational purposes to illustrate how real-world malware (such as the Shai-Hulud worm or the binding.gyp exploit) operates.
- [SAFE]: The skill instructions explicitly direct the agent to operate offline, avoid making network requests to unverified registries, and refrain from installing any code. It emphasizes that analysis is performed by reading files already present on the local disk.
- [SAFE]: Although the skill has an attack surface for indirect prompt injection (Category 8) because it is designed to analyze untrusted external dependency manifests and source code, it provides a structured reporting format and maintains a defensive posture. Given that the skill is no-code and lacks privileged tools, this surface does not pose a significant risk to the execution environment.
Audit Metadata