dependency-hygiene
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell and Python scripts (
scripts/audit-deps.shandscripts/audit_deps.py) designed to audit local project dependencies. These scripts execute standard development utilities such asdart,python3,grep, andls. The operations are confined to the project directory and the standard local package cache (~/.pub-cache), which is consistent with the skill's purpose of enforcing dependency hygiene. - [PROMPT_INJECTION]: The audit tools process project configuration files (
pubspec.yaml,pubspec.lock, andanalysis_options.yaml) which could theoretically contain malicious content intended to influence the agent. However, the scripts use structured parsing and restrictive regular expressions (e.g.,[a-z_]+for package names) to process these files, significantly mitigating the risk of injection or path traversal attacks. - Ingestion points: Content from
pubspec.yaml,pubspec.lock, andanalysis_options.yamlprocessed by shell and Python scripts. - Boundary markers: Not explicitly present in the data processing flow.
- Capability inventory: Execution of local development tools (
dart,python3,grep) and file system visibility within project and cache directories. - Sanitization: Use of restrictive regex filters for package names and standard JSON/shell processing for configuration data.
- [SAFE]: No malicious patterns such as credential exfiltration, persistence mechanisms, or obfuscation were detected. The skill promotes security best practices by encouraging supply chain auditing and strict dependency versioning.
Audit Metadata