night-market-config-catalog

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a 'Provenance and maintenance' section with bash commands (e.g., jq, rg, ls, head) for the agent to verify the project's configuration state. These commands are diagnostic and read-only, targeting non-sensitive project files like pyproject.toml and .claude/quality_gates.json without any network involvement.
  • [EXTERNAL_DOWNLOADS]: The documentation references standard development tools and security scanners, including bandit, ruff, and markitdown-mcp. These are well-known utilities mentioned in the context of the project's defined toolchain and do not represent suspicious remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:38 AM
Security Audit — agent-trust-hub — night-market-config-catalog