dev-workflow

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the official vendor CLI tool @contentstack/cli and seeding data from the contentstack/kickstart-stack-seed GitHub repository. These are documented as legitimate resources managed by the vendor.
  • [DATA_EXFILTRATION]: The skill promotes secure development practices by instructing users to copy environment variables to a local .env file, ensuring sensitive credentials from the Contentstack stack are not hardcoded or committed to version control.
  • [COMMAND_EXECUTION]: Instructions involve standard local development operations such as npm install, npm run dev, and the vendor's csdx CLI tools for authentication and project seeding, which align with the skill's intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:38 AM
Security Audit — agent-trust-hub — dev-workflow