extension-core-infrastructure

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus on legitimate development practices for integrating authentication and backend communication. The referenced packages (@caffeineai/, @icp-sdk/) and domains (caffeine.ai) are official resources from the vendor (caffeinelabs) or standard SDKs for the platform.
  • [COMMAND_EXECUTION]: The skill provides documentation on how developers should run pnpm install during migration, which is a standard development workflow and not an automated or malicious command execution.
  • [EXTERNAL_DOWNLOADS]: The skill lists NPM dependencies that need to be installed. These are well-known or vendor-specific packages (caffeinelabs) and do not represent a security risk when used as instructed in the developer guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:36 PM
Security Audit — agent-trust-hub — extension-core-infrastructure