alterlab-tubitak-proposal

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script scripts/scaffold_proposal.py via uv run. Analysis of the script shows it is dependency-free, uses only Python standard libraries, and is limited to benign text processing, regex-based validation of word counts, and generating Markdown scaffolds.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and frontmatter reference fetching live program guidelines and application forms from official Turkish government domains, specifically tubitak.gov.tr and its subdomains (ardeb-pbs.tubitak.gov.tr). These are well-known, authoritative sources necessary for the skill's stated purpose of proposal preparation.
  • [DATA_EXPOSURE]: The skill processes user-supplied proposal drafts and project titles. It organizes this data into standard Markdown templates. There is no evidence of credential harvesting, access to sensitive system paths (e.g., .ssh, .aws), or unauthorized data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 03:28 PM
Security Audit — agent-trust-hub — alterlab-tubitak-proposal