dev-dependency-management
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The provided script
scripts/dep_auditor.pyis a well-structured utility that uses only the Python standard library. It performs analytical tasks like scoring dependency health and identifying vulnerabilities from a provided JSON manifest without making network calls or executing external commands. - [SAFE]: The skill explicitly warns against security anti-patterns, such as ignoring lockfiles, using wildcard versions, and executing untrusted remote scripts (e.g.,
curl | bash). - [SAFE]: External tool recommendations are limited to industry-standard security and supply-chain utilities such as Trivy, Grype, Syft, Cosign, and FOSSA. These are documented for legitimate security workflows.
- [SAFE]: All configuration templates (Renovate, Dependabot, Docker, NPM, etc.) follow security-first principles, such as pinning versions, using exact installs, and minimizing attack surfaces.
- [SAFE]: No obfuscation, prompt injection attempts, or persistence mechanisms were detected in the instructions or code files.
Audit Metadata