agent-package-manager
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides bootstrap commands that download and execute scripts directly from the internet using shell piping (
curl | shandirm | iex). These commands target official Microsoft URL shorteners (aka.ms). - [EXTERNAL_DOWNLOADS]: The instructions reference external resources, including installation binaries and documentation, hosted on Microsoft's official GitHub Pages (
microsoft.github.io) and shortcut domains. - [DYNAMIC_EXECUTION]: The skill supports executing project-specific scripts defined in the
apm.ymlmanifest through theapm runandapm previewcommands. This allows for the execution of arbitrary commands stored within the project configuration. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external manifests (
apm.yml) and dependency trees from remote repositories. This represents an indirect injection surface where untrusted data could influence agent behavior. - Ingestion points: The agent reads configuration from
apm.yml,apm.lock.yaml, and remote package metadata during installation (SKILL.md, Step 1). - Boundary markers: The skill documentation notes that
apm installperforms security scans for hidden Unicode and content hash verification to mitigate risks (SKILL.md, Step 3.10). - Capability inventory: The APM CLI tools used by the skill can perform file system writes, network requests for package fetching, and shell command execution via defined scripts (references/command-workflows.md).
- Sanitization: The skill describes built-in enforcement policies, such as blocking transitive MCP servers and verifying content hashes during deployment (references/manifest-and-lockfile.md).
Audit Metadata