cordova-to-capacitor
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses dynamic context syntax (!) to execute shell commands when loaded. These commands (node -e and find) are designed to inspect the local project for relevant package.json dependencies and configuration files such as config.xml or capacitor.config.json. This provides the AI agent with a snapshot of the current project state to assist in the migration process.
- [EXTERNAL_DOWNLOADS]: The instructions guide the user to install various Node.js packages. These include official @capacitor plugins and @capgo vendor-provided tools for live updates and biometrics. All identified sources and packages are industry-standard or vendor-owned and present no inherent security risk in this context.
Audit Metadata