data-fair-processings
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill provides explicit instructions to avoid shell injection by using
execFileinstead ofexecwhen running external commands likeunzip. Evidence found intypescript-migration.md. It also references official vendor packages and GitHub Actions from the@data-fairorganization, which are consistent with the skill's purpose. Evidence found infile-templates.md. - [DYNAMIC_EXECUTION]: The plugin architecture relies on dynamic
import()to load specific logic such as transforms and schemas based on the processing configuration. This is documented inSKILL.mdandtypescript-migration.mdas the standard mechanism for the platform's plugin system. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a secure handling pattern for sensitive data. The
preparefunction is designed to move secrets (passwords, API keys) from the user-facing configuration to a protectedsecretscontext, preventing accidental exposure in the main configuration. Evidence found inSKILL.mdandconfig-schema.md.
Audit Metadata