dep-security

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The README.md file provides an installation command (npx skills add KrishnaAgarwal7531/skills- --skill dep-security) that downloads and installs the skill from a personal GitHub repository belonging to an unverified user. This deviates from the expected vendor source and presents a supply chain risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web pages, which is a common vector for indirect prompt injection attacks.
  • Ingestion points: The skill uses tinyfish agent run to scrape content from cve.mitre.org, github.com/advisories, npmjs.com/advisories, and nvd.nist.gov (SKILL.md).
  • Boundary markers: The agent prompts include "STRICT RULES" intended to limit the scope of the LLM's actions and enforce specific JSON output structures.
  • Capability inventory: The skill executes shell commands using the tinyfish CLI, performs parallel execution using shell backgrounding (&) and wait, and writes temporary data to /tmp (SKILL.md).
  • Sanitization: The skill relies solely on instructions within the prompt to filter external data; it lacks automated validation or sanitization of the scraped content before processing.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the tinyfish CLI to execute web scraping agents and manage data flow. It utilizes shell-specific features like command piping, redirection to the /tmp directory, and process synchronization via wait.
  • [EXTERNAL_DOWNLOADS]: The skill performs automated network requests to fetch security data from public databases, including GitHub's official advisory feed and the MITRE CVE database.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 12:12 AM
Security Audit — agent-trust-hub — dep-security