yy-frontend-style-bem-optimizer
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
git diff --name-only HEADandgit diff --cached --name-onlyfor identifying changed files when a specific file range is not provided by the user. These commands are used solely for local file discovery and do not include user-interpolated input, minimizing the risk of command injection.- [SAFE]: The skill references established external resources including the official BEM naming documentation (getbem.com) and the open-source csscomb.js repository on GitHub. These are well-known services within the technology industry and are used neutrally for configuration and standards reference.- [SAFE]: No patterns of obfuscation, hardcoded credentials, or data exfiltration were detected. The skill maintains a clear separation between its processing logic and system-level operations, requiring user confirmation before applying file changes.
Audit Metadata