skills/black12-ag/claude-skill/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses bunx to download and execute the @codewithbeto/ship package from the NPM registry.
  • [REMOTE_CODE_EXECUTION]: The execution of bunx @codewithbeto/ship involves running remote code fetched at runtime to scaffold the project.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands for project initialization, including bunx for scaffolding and bun install for dependency resolution.
  • [CREDENTIALS_UNSAFE]: The CLI tool accepts RevenueCat API keys via flags (--rc-key-ios, --rc-key-android). While these are used for project configuration, providing secrets as command-line arguments is a standard but sensitive practice that can lead to exposure in local logs or process lists.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:57 PM
Security Audit — agent-trust-hub — ship