dependency-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external dependency files (e.g., package.json, requirements.txt), which creates a potential surface for indirect prompt injection if those files contain malicious instructions disguised as data.
- Ingestion points: Project dependency configuration files accessed via the
file-readcapability. - Boundary markers: The instructions do not define specific delimiters or clear 'ignore' directives to prevent the agent from potentially following instructions embedded within the audited files.
- Capability inventory: The skill is highly restricted, with no
network,shell, orfile-writecapabilities allowed, which significantly limits the impact of any potential injection. - Sanitization: No explicit sanitization or structured parsing requirements are specified for the raw file content before the agent evaluates it.
- [METADATA_POISONING]: The skill's YAML frontmatter includes self-assigned safety metrics which could be misleading if relied upon as authoritative.
- Evidence: The metadata fields
trust-score: 93andlast-audited: '2026-02-03'are claims provided by the skill author about its own security status. As per standard security auditing, these self-reported values should not be treated as a guarantee of safety.
Audit Metadata