cali-product-ads

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation in references/cli-tools/ provides instructions for the manual installation of external plugins and extensions from GitHub and NPM registries, including cursor/plugins, PriNova/pi-agent-codebase-workflows, and @juicesharp/rpiv-todo. These are presented as optional environmental setup steps for the user.
  • [COMMAND_EXECUTION]: The reference files describe how the AI agent should interact with various CLI tools (e.g., agent_browser, plannotator, subagent) depending on which harness is detected (Pi, OpenCode, Claude Code, or Codex).
  • [SAFE]: The core skill content in SKILL.md consists of static educational material about advertising stages (Pre-contemplation to Maintenance) and corresponding ad categories. The skill's configuration explicitly sets disable-model-invocation: true, preventing the skill from triggering model actions autonomously.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 12:54 PM
Security Audit — agent-trust-hub — cali-product-ads