NYC

dependency-tracking

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOW
Full Analysis
  • [SAFE] (SAFE): No malicious code, prompt injection markers, or dangerous system-level operations were found.
  • [INDIRECT_PROMPT_INJECTION] (INFO): The skill processes task-related data (ingestion points: tasks array in DependencyTracker and DependencyResolution), but it has no capabilities (network, file-write, or command execution) that could be exploited via malicious input.
  • [COMMAND_EXECUTION] (SAFE): Code blocks contain logic only and do not use subprocess, os.system, or eval.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 10:24 PM