nicelicense

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to run the nicelicense package from the npm registry using npx.- [COMMAND_EXECUTION]: Executes shell commands to automate license operations, including writing to the filesystem and updating project configuration files.- [PROMPT_INJECTION]: Potential for indirect prompt injection when the agent processes data from project files during license validation.
  • Ingestion points: Reads local LICENSE files via the --validate flag.
  • Boundary markers: Absent.
  • Capability inventory: File system writes and package.json modifications via the nicelicense tool.
  • Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 05:45 PM