sca-npm-audit
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands for dependency scanning and resolution. Evidence: Commands
npm audit --jsonandnpm audit fixare specified inSKILL.mdfor project analysis. - [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection as it processes data from an external file generated by a tool. Ingestion points:
npm-audit-results.jsonfile mentioned inSKILL.md. Boundary markers: Absent. Capability inventory: Execution of subprocesses and local file system modifications. Sanitization: No explicit validation or sanitization is mentioned for the command output before summarization. - [SAFE]: The skill relies on well-known, official tools and follows established developer workflows for security maintenance.
Audit Metadata