artifacts-builder

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (init-artifact.sh, bundle-artifact.sh) that orchestrate the creation and build process of a React project. These scripts execute various system and development commands including pnpm, npm, tar, sed, and du to manage project files and dependencies.
  • [EXTERNAL_DOWNLOADS]: The scripts perform extensive package installations from the official NPM registry (a well-known service) to set up the development environment. This includes framework tools (Vite, React), styling libraries (Tailwind CSS, shadcn/ui components), and build utilities (Parcel, html-inline).
  • [DYNAMIC_EXECUTION]: The init-artifact.sh script uses node -e to execute inline JavaScript for programmatically updating project configuration files (tsconfig.json). This is used specifically to inject path aliases required by the shadcn/ui framework.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — artifacts-builder