dependency-vulnerability-scanner
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the OWASP Dependency-Check release archive from its official GitHub repository.
- [COMMAND_EXECUTION]: Uses the Bash tool to execute standard package manager commands and security audit utilities including npm, yarn, pip, gem, snyk, and license-checker.
- [REMOTE_CODE_EXECUTION]: Downloads and runs a shell script contained within the OWASP Dependency-Check distribution fetched from a trusted source.
Audit Metadata