dependency-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external dependency files (e.g., package.json, requirements.txt), which creates a potential surface for indirect prompt injection if those files contain malicious instructions disguised as data.
  • Ingestion points: Project dependency configuration files accessed via the file-read capability.
  • Boundary markers: The instructions do not define specific delimiters or clear 'ignore' directives to prevent the agent from potentially following instructions embedded within the audited files.
  • Capability inventory: The skill is highly restricted, with no network, shell, or file-write capabilities allowed, which significantly limits the impact of any potential injection.
  • Sanitization: No explicit sanitization or structured parsing requirements are specified for the raw file content before the agent evaluates it.
  • [METADATA_POISONING]: The skill's YAML frontmatter includes self-assigned safety metrics which could be misleading if relied upon as authoritative.
  • Evidence: The metadata fields trust-score: 93 and last-audited: '2026-02-03' are claims provided by the skill author about its own security status. As per standard security auditing, these self-reported values should not be treated as a guarantee of safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:43 AM
Security Audit — agent-trust-hub — dependency-auditor