agent-package-manager

Pass

Audited by Gen Agent Trust Hub on Feb 21, 2026

Risk Level: SAFE
Full Analysis
  • [External Downloads] (SAFE): The documentation mentions installing pyyaml and skills-ref via pip. Both are standard tools for the skill's purpose, and no untrusted remote script downloads were found.\n- [Command Execution] (SAFE): The shell scripts use standard Unix utilities (find, grep, awk) for local filesystem validation. While some scripts contain syntax errors (e.g., corrupted loops), no execution of untrusted or dynamic strings was detected.\n- [Data Exposure & Exfiltration] (SAFE): No evidence of network communication or unauthorized access to sensitive files (such as SSH keys or API credentials) was found.\n- [Prompt Injection] (SAFE): The instructions and prompts are focused on structural validation and scaffolding; they do not contain instructions aimed at bypassing AI safety protocols or extracting system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 21, 2026, 04:24 PM