skills/tartinerlabs/skills/deps/Gen Agent Trust Hub

deps

Pass

Audited by Gen Agent Trust Hub on May 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configures CI workflows that download GitHub Actions. It references official actions from the 'actions/' organization and a third-party action, 'tartinerlabs/lockfile-integrity', which is provided by the skill's vendor and pinned to a specific commit SHA for security.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands for package managers (pnpm, npm, yarn, bun) and the GitHub CLI (gh) to detect configurations and perform security audits.\n- [PROMPT_INJECTION]: The skill analyzes external configuration data (package.json and lockfiles) to determine applicable security rules. 1. Ingestion points: Reads 'package.json', lockfiles, and '.github/workflows/' files. 2. Boundary markers: None present. 3. Capability inventory: File system modification and shell execution of package manager tools. 4. Sanitization: The skill implements configuration hardening based on the project's existing state.
Audit Metadata
Risk Level
SAFE
Analyzed
May 28, 2026, 05:08 AM
Security Audit — agent-trust-hub — deps