skills/levnikolaevich/claude-code-skills/ln-820-dependency-optimization-coordinator/Gen Agent Trust Hub
ln-820-dependency-optimization-coordinator
Pass
Audited by Gen Agent Trust Hub on Apr 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches support files and runtime scripts from the author's official GitHub repository (
github.com/levnikolaevich/claude-code-skills) when they are missing from the local environment. \n- [COMMAND_EXECUTION]: Executes shell commands includingnodefor its internal runtime,npm auditfor Node.js analysis,dotnet list packagefor .NET, andpip-auditfor Python. \n- [EXTERNAL_DOWNLOADS]: Recommends the installation of thepip-auditpackage viapipto facilitate security scanning of Python dependencies. \n- [PROMPT_INJECTION]: The skill ingests untrusted project data through manifest files, representing an indirect prompt injection surface. Ingestion points: Project manifests likepackage.json,requirements.txt, andpyproject.tomlidentified in Phase 1. Boundary markers: None present in the instructions. Capability inventory: Shell command execution (node, npm, dotnet, pip-audit) and delegation to sub-skills. Sanitization: No explicit validation or escaping of manifest content is documented.
Audit Metadata