agent-package-manager

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides bootstrap commands that download and execute scripts directly from the internet using shell piping (curl | sh and irm | iex). These commands target official Microsoft URL shorteners (aka.ms).
  • [EXTERNAL_DOWNLOADS]: The instructions reference external resources, including installation binaries and documentation, hosted on Microsoft's official GitHub Pages (microsoft.github.io) and shortcut domains.
  • [DYNAMIC_EXECUTION]: The skill supports executing project-specific scripts defined in the apm.yml manifest through the apm run and apm preview commands. This allows for the execution of arbitrary commands stored within the project configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external manifests (apm.yml) and dependency trees from remote repositories. This represents an indirect injection surface where untrusted data could influence agent behavior.
  • Ingestion points: The agent reads configuration from apm.yml, apm.lock.yaml, and remote package metadata during installation (SKILL.md, Step 1).
  • Boundary markers: The skill documentation notes that apm install performs security scans for hidden Unicode and content hash verification to mitigate risks (SKILL.md, Step 3.10).
  • Capability inventory: The APM CLI tools used by the skill can perform file system writes, network requests for package fetching, and shell command execution via defined scripts (references/command-workflows.md).
  • Sanitization: The skill describes built-in enforcement policies, such as blocking transitive MCP servers and verifying content hashes during deployment (references/manifest-and-lockfile.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:54 PM
Security Audit — agent-trust-hub — agent-package-manager