freemius-core
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for dependency management (
npm install @freemius/sdk) and UI component installation via the shadcn CLI (npx shadcn@latest add ...).- [EXTERNAL_DOWNLOADS]: The skill fetches configuration files and technical documentation from the vendor's official domains, specificallyfreemius.comandshadcn.freemius.com.- [DATA_EXFILTRATION]: To streamline the integration process, the skill includes instructions for the agent to scan local repository files, including.env,.env.example, andREADME.md, to detect and reuse existing product identifiers and configuration keys. These operations are performed within the local environment to assist the developer.- [PROMPT_INJECTION]: The skill directs the agent to analyze the user's codebase and configuration files to autonomously derive monetization intent and setup requirements, which is an expected instructional behavior for this utility.
Audit Metadata