kit-author

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • Remote Script Execution: The documentation includes examples of installing tools using shell pipes from remote sources, such as code-server.dev. These patterns are presented in an educational context with advice on verifying outcomes.
  • Workspace Protection: The skill describes how kits can manipulate workspace files and provides specific guidance in the 'Pitfalls' section on avoiding accidental data loss or unauthorized overlays.
  • Indirect Prompt Injection Surface: The guide explains the system for providing agent instructions through kit metadata, documenting how this context is rendered and managed by the platform.
  • Credential Security: The skill details a robust credential handling model that uses a proxy-based injection system to protect sensitive tokens from direct exposure within sandbox environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 10:52 PM
Security Audit — agent-trust-hub — kit-author