agent-package-manager
Pass
Audited by Gen Agent Trust Hub on Feb 21, 2026
Risk Level: SAFE
Full Analysis
- [External Downloads] (SAFE): The documentation mentions installing
pyyamlandskills-refvia pip. Both are standard tools for the skill's purpose, and no untrusted remote script downloads were found.\n- [Command Execution] (SAFE): The shell scripts use standard Unix utilities (find,grep,awk) for local filesystem validation. While some scripts contain syntax errors (e.g., corrupted loops), no execution of untrusted or dynamic strings was detected.\n- [Data Exposure & Exfiltration] (SAFE): No evidence of network communication or unauthorized access to sensitive files (such as SSH keys or API credentials) was found.\n- [Prompt Injection] (SAFE): The instructions and prompts are focused on structural validation and scaffolding; they do not contain instructions aimed at bypassing AI safety protocols or extracting system prompts.
Audit Metadata