senior-fullstack
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python scripts for project scaffolding and code analysis. These scripts perform local filesystem operations (creating directories, writing files, and reading source code) using standard Python libraries. They do not invoke arbitrary shell commands or execute subprocesses.
- [DATA_EXPOSURE]: The code quality analyzer reads local project files to perform regex-based security and quality checks. It calculates complexity and identifies potential hardcoded secrets or vulnerabilities. No network operations were found that would exfiltrate this data.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any remote downloads or fetch external scripts at runtime. All template contents and analysis logic are contained within the skill's own files.
- [CREDENTIALS_UNSAFE]: While the skill contains references to credentials (e.g., in configuration templates and workflow guides), these are explicitly documented as placeholders (e.g., 'change-me-in-production') or used in local development examples (e.g., Docker Compose configurations). No real secrets are hardcoded.
Audit Metadata