editing-cordis-compositions

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing optional subagent providers using the dsh CLI (e.g., dsh plugin --profile <name> add @deepseek-ai/dsh-subagent-codex). The packages are official vendor resources from the deepseek-ai organization.
  • [PRIVILEGE_ESCALATION]: The documentation describes using the sandbox_permissions mechanism to grant the agent write access to the user's preset directory (e.g., ~/.dsh/.agent-presets/), which resides outside the default session workspace. This is a documented platform feature for configuration management that requires user approval.
  • [DYNAMIC_EXECUTION]: The skill mentions cordis_mount, which allows for evaluating JavaScript in the live runtime. This is presented as a temporary tool for probing and service inspection rather than a permanent execution method, and its use is restricted to authoring and verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:44 AM
Security Audit — agent-trust-hub — editing-cordis-compositions