polystella-consumer

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • Safe Credential Management: The instructions explicitly advise against committing sensitive credentials (like R2 keys or AI tokens) to version control. It recommends using environment variables via .env files and dotenv/config, which aligns with security best practices for secret management.
  • Trusted Dependency Integration: The skill guides users to install the @cloudflare/polystella package from npm. As this is an official resource from the documented author, it is considered a legitimate and expected dependency for this toolset.
  • Content Processing Surface: As a localization tool, the skill facilitates the processing of content files (Markdown, JSON, etc.) through AI providers for translation. While this is the core intended functionality, users should ensure that the source content processed by the tool is from trusted contributors, which is a standard consideration for any AI-integrated workflow.
  • Environment-Based Cache Dispatching: The skill describes a branch-isolated caching mechanism for Cloudflare R2. This design ensures that local development builds or preview environments do not inadvertently overwrite production assets, providing a safe operational boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 08:52 PM
Security Audit — agent-trust-hub — polystella-consumer