add-to-site
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local commands to verify code integrity using
bun tscandbun run lintwithin the portfolio's directory. This is standard developer workflow behavior and is restricted to the user's local repository path. - [DATA_EXPOSURE]: The skill reads from local file paths (e.g.,
~/Developer/repos/dividendsolo/) to gather project metadata such as descriptions and technical stacks. This is consistent with the skill's primary purpose of porting project info to a portfolio site and all identified resources belong to the skill author's context.
Audit Metadata