oss-sponsors-brand-strategy

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted data to generate its recommendations.
  • Ingestion points: As described in SKILL.md and references/target-discovery-and-scoring.md, the agent is instructed to ingest and resolve dependency trees from external files including lockfiles, SBOMs, and repository manifests such as .github/FUNDING.yml.
  • Capability inventory: The agent uses the ingested data to build ranked lists, suggest budget allocations, and draft maintainer outreach notes. It does not utilize these inputs for high-privilege operations such as arbitrary command execution or writing to system files.
  • Boundary markers: The instructions lack explicit boundary markers or warnings to ignore instructions that might be embedded within the processed manifest files.
  • Sanitization: While the skill relies on structured APIs like deps.dev for resolution, there is no mention of sanitizing the raw strings found in manifests before they are interpolated into the agent's context.
  • [EXTERNAL_DOWNLOADS]: The skill fetches metadata from external services to perform its core analysis.
  • Details: It retrieves dependency health signals, criticality scores, and funding metadata from Google's deps.dev API and GitHub's repository manifests.
  • Source: These are well-known technology services used appropriately for the skill's stated purpose of dependency analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:50 PM
Security Audit — agent-trust-hub — oss-sponsors-brand-strategy