cali-product-trust-building

Warn

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The reference files references/cli-tools/codequality-review.md and references/cli-tools/safe-change.md provide instructions to install external code using pi install from GitHub repositories including github.com/cursor/plugins and github.com/PriNova/pi-agent-codebase-workflows. These sources are outside the verified vendor scope.
  • [EXTERNAL_DOWNLOADS]: Multiple reference files specify requirements for third-party NPM packages from various scopes (e.g., @juicesharp/rpiv-ask-user-question, @plannotator/pi-extension, @backnotprop/plannotator, @juicesharp/rpiv-todo) which are necessary to enable the documented tool functionality.
  • [COMMAND_EXECUTION]: The skill's reference documentation extensively details the usage of shell-based commands and custom CLI tools (such as plannotator, safe-change, and /sw-setphase) for environment management, automated browsing, and workflow state control across different agent harnesses.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 12:53 PM
Security Audit — agent-trust-hub — cali-product-trust-building