npm-package-comparator

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes bash templates that interpolate user-supplied package names into shell commands for the tinyfish CLI. If the agent does not sanitize these inputs before execution, it could lead to command injection.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @tiny-fish/cli package from the npm registry. This is a tool provided by the skill vendor for legitimate functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content fetched from third-party websites including npmjs.com and github.com. This content could be manipulated by package maintainers to influence the agent's summary or recommendations.
  • Ingestion points: External package data and repository metadata fetched via the tinyfish agent.
  • Boundary markers: The skill instructs sub-agents to follow strict rules (e.g., "Read only what is visible", "Return JSON") to constrain the processing of external data.
  • Capability inventory: The skill can execute shell commands, write data to the /tmp directory, and read those files for synthesis.
  • Sanitization: No explicit sanitization or escaping of the scraped text is performed before it is interpolated into the final comparison synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:04 AM
Security Audit — agent-trust-hub — npm-package-comparator