data-fair-processings

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill provides explicit instructions to avoid shell injection by using execFile instead of exec when running external commands like unzip. Evidence found in typescript-migration.md. It also references official vendor packages and GitHub Actions from the @data-fair organization, which are consistent with the skill's purpose. Evidence found in file-templates.md.
  • [DYNAMIC_EXECUTION]: The plugin architecture relies on dynamic import() to load specific logic such as transforms and schemas based on the processing configuration. This is documented in SKILL.md and typescript-migration.md as the standard mechanism for the platform's plugin system.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a secure handling pattern for sensitive data. The prepare function is designed to move secrets (passwords, API keys) from the user-facing configuration to a protected secrets context, preventing accidental exposure in the main configuration. Evidence found in SKILL.md and config-schema.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 06:23 AM
Security Audit — agent-trust-hub — data-fair-processings