shaders-cursor-ripples

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'shaders' package via the npm registry. The documentation explicitly identifies this as a proprietary, non-OSS dependency and provides links to official documentation and the package registry for verification.
  • [COMMAND_EXECUTION]: Provides standard shell commands for dependency management (npm install). These are routine operations for the described task and do not involve suspicious parameters or piped execution.
  • [DATA_EXFILTRATION]: The documentation mentions the 'disableTelemetry' option for the library. Providing instructions to disable telemetry is a recommended privacy practice and no other network exfiltration patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 02:33 PM
Security Audit — agent-trust-hub — shaders-cursor-ripples