version-check

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands such as claude --version and npm view to retrieve installation status and registry metadata.
  • [COMMAND_EXECUTION]: A python3 one-liner is used to parse and display release timestamps from JSON data.
  • [COMMAND_EXECUTION]: The skill uses docker exec to run gh api commands within a containerized environment to search for bug reports.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the official CHANGELOG.md from the project's GitHub repository to identify recent fixes and potential regressions.
  • [EXTERNAL_DOWNLOADS]: Public sentiment data is retrieved from Reddit search results to identify version-specific issues reported by the community.
  • [PROMPT_INJECTION]: The skill ingests untrusted content from GitHub issue titles and Reddit posts; this creates an indirect prompt injection surface, though the risk is localized to the analysis of version stability.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 02:16 AM
Security Audit — agent-trust-hub — version-check