deps-audit
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill runs standard system commands including
npm audit,npm outdated, andgrepto analyze local project files (SKILL.md). - [EXTERNAL_DOWNLOADS]: The skill queries the official npm registry for package metadata and security advisories.
- [REMOTE_CODE_EXECUTION]: The skill includes a fallback to run
npm installif a lockfile is missing. This is a standard procedure for dependency auditing and uses the system's default package manager (SKILL.md). - [PROMPT_INJECTION]: The skill identifies a surface for indirect injection as it processes
package.jsonand source files from thesrc/directory. Evidence: Data enters atpackage.jsonandsrc/; no boundary markers are specified; capabilities includenpmcommands; no sanitization is defined (SKILL.md).
Audit Metadata