cli-developer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a legitimate technical resource for developers. It provides architecture patterns and code examples for well-known, industry-standard frameworks.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill actively promotes secure development practices by instructing users to store sensitive data in configuration files with restricted file permissions (e.g., chmod 600 for credentials.json).
  • [EXTERNAL_DOWNLOADS]: The skill mentions common, reputable libraries such as Commander.js, Typer, and Cobra. These references are for documentation and implementation purposes via standard package registries (NPM, PyPI, Go Modules) and do not involve downloading or executing untrusted code from unknown sources.
  • [COMMAND_EXECUTION]: Code examples include the use of execa in Node.js for functional testing of CLI tools. This is a standard practice for development workflows and does not expose the environment to arbitrary command injection, as the examples demonstrate controlled execution for testing purposes.
  • [DATA_EXFILTRATION]: There are no patterns suggesting data exfiltration. The skill's network-related mentions are limited to standard CLI behaviors like checking for updates or making documented API calls within the developer's own application context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — cli-developer