deps-dev

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches package metadata from Google's official deps.dev API (api.deps.dev). This is a well-known service for open-source dependency information.
  • [COMMAND_EXECUTION]: Executes a provided Python script scripts/get-versions.py to perform lookups. The script uses standard Python libraries (urllib, json) and properly sanitizes package names via URL encoding to prevent injection attacks.
  • [PROMPT_INJECTION]: Contains a directive 'DO NOT read script source code' which is intended to streamline the agent's workflow by focusing on tool usage rather than implementation analysis. No malicious instructions or safety bypasses were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 02:29 PM