cali-product-business-models

Warn

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Several reference files (e.g., safe-change.md, codequality-review.md, and todo.md) instruct users to download and install tools from third-party GitHub repositories and NPM packages. Mentioned sources include github.com/PriNova/pi-agent-codebase-workflows, github.com/cursor/plugins, and NPM packages like @juicesharp/rpiv-todo and @plannotator/pi-extension, which are not from verified trusted organizations.
  • [COMMAND_EXECUTION]: The documentation provides shell commands for installing these external dependencies, such as pi install git:github.com/cursor/plugins and npx skills add Prinova/pi-agent-codebase-workflows -a <cli> -g. The use of the -g (global) flag indicates that these installations modify the global system environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 12:53 PM
Security Audit — agent-trust-hub — cali-product-business-models