cali-product-trust-building
Warn
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The reference files
references/cli-tools/codequality-review.mdandreferences/cli-tools/safe-change.mdprovide instructions to install external code usingpi installfrom GitHub repositories includinggithub.com/cursor/pluginsandgithub.com/PriNova/pi-agent-codebase-workflows. These sources are outside the verified vendor scope. - [EXTERNAL_DOWNLOADS]: Multiple reference files specify requirements for third-party NPM packages from various scopes (e.g.,
@juicesharp/rpiv-ask-user-question,@plannotator/pi-extension,@backnotprop/plannotator,@juicesharp/rpiv-todo) which are necessary to enable the documented tool functionality. - [COMMAND_EXECUTION]: The skill's reference documentation extensively details the usage of shell-based commands and custom CLI tools (such as
plannotator,safe-change, and/sw-setphase) for environment management, automated browsing, and workflow state control across different agent harnesses.
Audit Metadata