never-publish-skill

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides guidance on modifying a local policy file (~/.agents/public-mirror-policy.json) to exclude specific folders from a public synchronization process.
  • [COMMAND_EXECUTION]: The skill includes a command to validate JSON syntax using python3 -c. This is a standard diagnostic practice for ensuring configuration file integrity.
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) to verify the status of workflow runs and repository contents. These operations are performed within the context of the user's repositories for legitimate verification purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 08:34 PM
Security Audit — agent-trust-hub — never-publish-skill