dev-dependency-management

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The provided script scripts/dep_auditor.py is a well-structured utility that uses only the Python standard library. It performs analytical tasks like scoring dependency health and identifying vulnerabilities from a provided JSON manifest without making network calls or executing external commands.
  • [SAFE]: The skill explicitly warns against security anti-patterns, such as ignoring lockfiles, using wildcard versions, and executing untrusted remote scripts (e.g., curl | bash).
  • [SAFE]: External tool recommendations are limited to industry-standard security and supply-chain utilities such as Trivy, Grype, Syft, Cosign, and FOSSA. These are documented for legitimate security workflows.
  • [SAFE]: All configuration templates (Renovate, Dependabot, Docker, NPM, etc.) follow security-first principles, such as pinning versions, using exact installs, and minimizing attack surfaces.
  • [SAFE]: No obfuscation, prompt injection attempts, or persistence mechanisms were detected in the instructions or code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — dev-dependency-management