verification

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several project-specific scripts via npm, including npm run compile, npm run lint, npm run test, npm run bundle, and npm run check:dupes.
  • [COMMAND_EXECUTION]: To ensure the environment is correctly set up, the instructions direct the agent to run npm install if expected local binaries are missing from the node_modules directory.
  • [COMMAND_EXECUTION]: The agent is instructed to use local binaries located in node_modules/.bin/ (such as jest, knip, and effect-language-service) rather than using npx. The documentation explicitly notes this is to avoid potential security risks from typosquatted package names on the public registry.
  • [COMMAND_EXECUTION]: A troubleshooting instruction includes rm -rf ~/.npm/_npx to clear the local npx cache if package resolution errors occur.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:03 AM
Security Audit — agent-trust-hub — verification