dotnet-version-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the execution of various
dotnetCLI commands, includingdotnet build,dotnet test,dotnet tool install, anddotnet outdated. These are standard operations for .NET development and migration tasks. - [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install global tools using the .NET CLI.
- It references the official Microsoft
upgrade-assistanttool. - It references the
dotnet-outdated-toolfrom the establisheddotnet-outdatedGitHub repository. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external project data, which introduces a surface for indirect prompt injection.
- Ingestion points: The skill consumes structured output from
skill:dotnet-version-detection(as described in the introduction) and reads local project files like.csproj,global.json, andDirectory.Packages.props. - Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for the data ingested from the external detection skill or project files.
- Capability inventory: The skill utilizes shell command execution capabilities (
dotnetCLI tools) and file modification via thedotnet outdated --upgradeandupgrade-assistant upgradecommands. - Sanitization: No explicit sanitization or validation of the input data from the detection skill or project files is described.
Audit Metadata