supply-chain-risk-auditor

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Executes the gh utility via bash to fetch dependency metadata such as star counts and issue status. This behavior is aligned with the skill's stated purpose of auditing supply chain health.
  • [DATA_EXFILTRATION]: Accesses local project files to identify dependencies. Data collected is used solely to generate a local markdown report within the workspace; no external exfiltration to non-whitelisted domains was detected.
  • [PROMPT_INJECTION]: The skill processes untrusted metadata. 1. Ingestion points: Dependency files and gh CLI output. 2. Boundary markers: Absent. 3. Capability inventory: Bash, Write, Read. 4. Sanitization: Absent. The risk is minimized by the skill's specific purpose and use of a trusted security auditing workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:23 AM