skills/findbene/skills/design-review/Gen Agent Trust Hub

design-review

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Bun installation script from the well-known service 'https://bun.sh/install'. The skill uses a hardcoded SHA-256 checksum ('bab8acfb046aac8c72407bdcce903957665d655d7acaa3e11c7c4616beae68dd') to verify the integrity of the installer before execution.
  • [REMOTE_CODE_EXECUTION]: Executes the verified Bun installation script via 'bash' if the required runtime is missing from the environment.
  • [COMMAND_EXECUTION]: Extensively uses shell commands to interact with the project and 'gstack' framework, including:
  • Executing localized helper scripts within the '~/.claude/skills/gstack/bin/' directory.
  • Utilizing 'eval' on the output of specific local scripts (e.g., 'gstack-slug') for environment configuration.
  • Modifying 'CLAUDE.md' to add routing rules, which is gated by a user confirmation step.
  • [DATA_EXFILTRATION]: Implements a telemetry system for logging skill usage metrics (duration, outcome). This feature is explicitly introduced to the user via an 'AskUserQuestion' prompt, allowing for anonymous, fully-disabled, or community-based reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 06:44 PM
Security Audit — agent-trust-hub — design-review