skills/alemtuzlak/skills/teach-me/Gen Agent Trust Hub

teach-me

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the 'marked.min.js' library from 'cdn.jsdelivr.net' in Phase 9. This is a well-known and standard Content Delivery Network used for distributing official software libraries.
  • [COMMAND_EXECUTION]: Executes 'npm install' within the skill's assets directory to fetch the Shiki highlighter. This is a standard dependency management task necessary for the skill's stated purpose of pre-rendering code blocks.
  • [COMMAND_EXECUTION]: Uses local shell commands such as 'explorer.exe', 'start', and 'code' to open the generated course files and browser viewer for the user. These operations are transparent and consistent with the user's workflow.
  • [DATA_EXFILTRATION]: Accesses local memory files (specifically under the vendor-specific path 'C:/Users/AlemTuzlak/.claude/projects/F--projects/memory/') to retrieve the user's preferred output location. This is a legitimate state-management pattern for maintaining user configuration between sessions.
  • [REMOTE_CODE_EXECUTION]: While the skill executes a local Node.js build script ('build-html.mjs'), it is a distributed part of the skill used for static site generation. It does not execute arbitrary remote code or piped shell scripts from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:10 PM
Security Audit — agent-trust-hub — teach-me