fw-publish
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements secure credential management by instructing users to use system keychains or configuration files with restricted permissions (chmod 600 on ~/.cursor/mcp.json). It provides explicit warnings against committing API keys to version control.\n- [COMMAND_EXECUTION]: The skill uses local shell commands (fdk, zip, unzip, jq, curl) to perform app validation and packaging. These are standard operations for the Freshworks development lifecycle and are executed with user awareness.\n- [EXTERNAL_DOWNLOADS]: The skill interacts with Freshworks' official MCP server (https://mcp.freshworks.dev) and authorized S3 infrastructure for app uploads. These network requests are restricted to the intended purpose of app deployment to the vendor's marketplace.
Audit Metadata