ln-821-npm-upgrader

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches its own reference files and components from the author's official GitHub repository (github.com/levnikolaevich/claude-code-skills) using WebFetch when local files are not available.
  • [COMMAND_EXECUTION]: The skill executes standard development tools including npm, yarn, pnpm, and npx to perform dependency audits, version checks, and package installations.
  • [PROMPT_INJECTION]: The skill ingests external data from web searches and documentation queries to identify migration steps. While this represents an indirect prompt injection surface, the risk is mitigated by the skill's specific focus on technical migration guides.
  • [DATA_EXFILTRATION]: The skill records execution results and summary artifacts to the project's local directory (.hex-skills/runtime-artifacts/) for session tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:39 PM