dotnet-version-upgrade

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the execution of various dotnet CLI commands, including dotnet build, dotnet test, dotnet tool install, and dotnet outdated. These are standard operations for .NET development and migration tasks.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install global tools using the .NET CLI.
  • It references the official Microsoft upgrade-assistant tool.
  • It references the dotnet-outdated-tool from the established dotnet-outdated GitHub repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external project data, which introduces a surface for indirect prompt injection.
  • Ingestion points: The skill consumes structured output from skill:dotnet-version-detection (as described in the introduction) and reads local project files like .csproj, global.json, and Directory.Packages.props.
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for the data ingested from the external detection skill or project files.
  • Capability inventory: The skill utilizes shell command execution capabilities (dotnet CLI tools) and file modification via the dotnet outdated --upgrade and upgrade-assistant upgrade commands.
  • Sanitization: No explicit sanitization or validation of the input data from the detection skill or project files is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:31 AM
Security Audit — agent-trust-hub — dotnet-version-upgrade