dependency-hygiene

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell and Python scripts (scripts/audit-deps.sh and scripts/audit_deps.py) designed to audit local project dependencies. These scripts execute standard development utilities such as dart, python3, grep, and ls. The operations are confined to the project directory and the standard local package cache (~/.pub-cache), which is consistent with the skill's purpose of enforcing dependency hygiene.
  • [PROMPT_INJECTION]: The audit tools process project configuration files (pubspec.yaml, pubspec.lock, and analysis_options.yaml) which could theoretically contain malicious content intended to influence the agent. However, the scripts use structured parsing and restrictive regular expressions (e.g., [a-z_]+ for package names) to process these files, significantly mitigating the risk of injection or path traversal attacks.
  • Ingestion points: Content from pubspec.yaml, pubspec.lock, and analysis_options.yaml processed by shell and Python scripts.
  • Boundary markers: Not explicitly present in the data processing flow.
  • Capability inventory: Execution of local development tools (dart, python3, grep) and file system visibility within project and cache directories.
  • Sanitization: Use of restrictive regex filters for package names and standard JSON/shell processing for configuration data.
  • [SAFE]: No malicious patterns such as credential exfiltration, persistence mechanisms, or obfuscation were detected. The skill promotes security best practices by encouraging supply chain auditing and strict dependency versioning.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 01:01 PM
Security Audit — agent-trust-hub — dependency-hygiene