visual-recap

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the Mermaid diagramming library from the JSDelivr CDN. This is a well-known service for front-end assets and the reference is used here for legitimate UI rendering purposes within the generated artifact.
  • [CREDENTIALS_UNSAFE]: The skill includes a proactive 'Secret Redaction' security protocol. It instructs the agent to mask sensitive patterns such as API keys, credentialed URIs, and PEM blocks found in code diffs before they are emitted into the HTML recap.
  • [COMMAND_EXECUTION]: The skill uses standard version control CLI tools (git, gh) to read repository data. It also suggests using a local Python web server to view the generated HTML, which is a standard and safe developer practice for local file browsing.
  • [DATA_EXFILTRATION]: No network-based exfiltration patterns were detected. The skill implements a reviewer feedback loop via the system clipboard, ensuring that project-related observations remain under user control within the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 10:51 AM
Security Audit — agent-trust-hub — visual-recap