understand-dashboard

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the $ARGUMENTS variable in shell command blocks without sanitization, creating a potential command injection surface. Ingestion points: Project path via $ARGUMENTS in SKILL.md. Boundary markers: Absent. Capability inventory: realpath, pnpm install, npx vite. Sanitization: No input validation or escaping before interpolation into shell commands.\n- [EXTERNAL_DOWNLOADS]: The skill invokes pnpm install and npx, which fetch Node.js packages from the official npm registry. these are standard development operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 04:27 AM
Security Audit — agent-trust-hub — understand-dashboard