deco-start-architecture

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Architectural Documentation. The skill consists exclusively of Markdown files providing a technical reference for the @decocms/start framework. It does not contain executable code, malicious instructions, or bypass attempts.
  • [COMMAND_EXECUTION]: The documentation describes an invocation handler (/deco/invoke) used to execute server-side loaders and actions by key. This is a standard RPC mechanism within the framework architecture and operates on a pre-defined registry of functions.
  • [DATA_EXFILTRATION]: The files detail endpoints for the Deco CMS admin protocol (e.g., /live/_meta, /.decofile). These are used for legitimate content synchronization and metadata exchange between the storefront and the vendor's official admin domain (admin.deco.cx).
  • [NO_CODE]: The analyzed skill content consists entirely of documentation and architectural guides with no referenced scripts or executable binaries attached in the provided fileset.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 12:15 PM
Security Audit — agent-trust-hub — deco-start-architecture