ln-821-npm-upgrader
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches its own reference files and components from the author's official GitHub repository (
github.com/levnikolaevich/claude-code-skills) usingWebFetchwhen local files are not available. - [COMMAND_EXECUTION]: The skill executes standard development tools including
npm,yarn,pnpm, andnpxto perform dependency audits, version checks, and package installations. - [PROMPT_INJECTION]: The skill ingests external data from web searches and documentation queries to identify migration steps. While this represents an indirect prompt injection surface, the risk is mitigated by the skill's specific focus on technical migration guides.
- [DATA_EXFILTRATION]: The skill records execution results and summary artifacts to the project's local directory (
.hex-skills/runtime-artifacts/) for session tracking.
Audit Metadata