AGENT LAB: SKILLS

nuget-manager

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [Command Execution] (SAFE): The skill utilizes standard dotnet CLI commands (add, remove, search, restore) to perform its stated purpose of NuGet package management. These operations are performed on the local project environment as expected.
  • [Indirect Prompt Injection] (SAFE): While the skill takes user-provided package names and paths as input, it does so within the scope of a defined package management workflow. 1. Ingestion points: User instructions for package names, versions, and project paths. 2. Boundary markers: Absent. 3. Capability inventory: Subprocess execution of the dotnet CLI and file-system modification of .csproj and .props files. 4. Sanitization: No explicit sanitization of input strings is defined in the instructions, but the risk is aligned with the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:51 PM