skills/dotlas/skills/impeccable/Gen Agent Trust Hub

impeccable

Warn

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/pin.mjs performs filesystem writes to hidden harness directories (e.g., .claude/skills, .cursor/skills, .agents/skills) to create standalone command shortcuts, effectively creating new agent capabilities.
  • [COMMAND_EXECUTION]: The script scripts/hook-admin.mjs modifies agent configuration files like .claude/settings.local.json, .codex/hooks.json, and .cursor/hooks.json to install design detector hooks.
  • [COMMAND_EXECUTION]: The script scripts/live-copy-edit-agent.mjs spawns the codex and claude CLI tools using high-risk flags that bypass user approvals and sandboxes, such as --dangerously-bypass-approvals-and-sandbox and --permission-mode bypassPermissions.
  • [COMMAND_EXECUTION]: The primary instructions in SKILL.md require the agent to execute several local Node.js scripts (context.mjs, palette.mjs, detect.mjs, etc.) to gather project context and run analysis.
  • [EXTERNAL_DOWNLOADS]: The script scripts/context.mjs performs an automated version check by making network requests to https://impeccable.style/api/version upon session initialization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 24, 2026, 11:31 AM
Security Audit — agent-trust-hub — impeccable