antigravity-lazy-packs

Pass

Audited by Gen Agent Trust Hub on Jun 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill automates the installation of several third-party tools and MCP servers from public registries, including notebooklm-mcp-cli via uv, @bitbonsai/mcpvault and @googleworkspace/cli via npm, and firebase-tools via npx. These are required for the skill's stated functionality of integrating various services into the agent environment.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of authentication commands and service configurations, such as gh auth login, firebase login, and nlm login. These commands are standard procedures for establishing secure connections to external platforms.
  • [SAFE]: The documentation emphasizes security best practices, specifically instructing the user and the agent not to commit sensitive files (like client_secret.json), tokens, or API keys to version control. It also advocates for reviewing changes with git diff before committing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 9, 2026, 01:26 PM
Security Audit — agent-trust-hub — antigravity-lazy-packs