post-purchase-sequence

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's initialization logic manages environment setup, such as determining the installation root and checking for updates using local scripts relative to the skill's directory.
  • [SAFE]: A telemetry mechanism is included to log anonymous usage data (skill name and active product name). This system is designed to be transparent, explicitly prompting the user for consent before activation.
  • [SAFE]: Local configuration and workspace state are maintained within a dedicated directory (~/.rmbc-skills), following standard practices for managing user preferences and project-specific metadata.
  • [SAFE]: External links, such as the introductory video, are presented to the user through an interactive prompt and are only opened upon explicit confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 01:36 PM
Security Audit — agent-trust-hub — post-purchase-sequence