stelow-product-marketplace-playbook

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides utility scripts and references that use standard system commands like bash, node, git, and npx for configuration management and tool execution. For example, read-config.md uses node -e to parse local configuration files.
  • [EXTERNAL_DOWNLOADS]: The documentation references multiple third-party tools and packages available via NPM and GitHub, including @earendil-works/pi-agent-browser, @tintinweb/pi-subagents, and repositories such as github.com/cursor/plugins. These are presented as extensions for the stelow framework.
  • [SAFE]: No malicious behavior, obfuscation, or safety bypasses were identified. The core playbook content in SKILL.md is purely instructional business strategy with tool invocation disabled via disable-model-invocation: true.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 10:48 AM
Security Audit — agent-trust-hub — stelow-product-marketplace-playbook