Agent Skill trust card
Dependency Audit & SBOM
community · recorded version or snapshot 1.0.0
Audit npm, pip, and cargo dependencies: CVE scanning, SBOM generation, license compliance, automated PRs with Renovate/Dependabot.
Metadata reviewed No listed warning
Source and identity
- Publisher
- community
- Namespace
- Not recorded
- Recorded version / snapshot
- 1.0.0
- License
- Not recorded
- Artifact SHA-256
- Not recorded — a source snapshot alone does not pin an artifact
Declared access
Review every permission against your own environment and least-privilege policy.
No permissions were recorded. This does not prove the component requires none.
Required secrets
Generated examples use placeholders. Never paste real secrets into ToolDix.
No required secrets are declared in the current metadata.
Compatibility and connection
Clients
- Codex
- Claude
- Cursor
- OpenClaw
Runtimes
No runtime is recorded.
Transports
No transport is recorded.
Authentication
No authentication method is recorded.
Evidence
- Canonical source
canonical · observed Jul 15, 2026