npm-package-comparator
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes bash templates that interpolate user-supplied package names into shell commands for the
tinyfishCLI. If the agent does not sanitize these inputs before execution, it could lead to command injection. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@tiny-fish/clipackage from the npm registry. This is a tool provided by the skill vendor for legitimate functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content fetched from third-party websites including npmjs.com and github.com. This content could be manipulated by package maintainers to influence the agent's summary or recommendations.
- Ingestion points: External package data and repository metadata fetched via the
tinyfishagent. - Boundary markers: The skill instructs sub-agents to follow strict rules (e.g., "Read only what is visible", "Return JSON") to constrain the processing of external data.
- Capability inventory: The skill can execute shell commands, write data to the
/tmpdirectory, and read those files for synthesis. - Sanitization: No explicit sanitization or escaping of the scraped text is performed before it is interpolated into the final comparison synthesis.
Audit Metadata