dev-cache
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- External Resource Management: The skill utilizes a
CachedToolPolicyandmaterialize()function to fetch external executables via HTTPS. While this involves downloading remote code, the skill enforces security measures such as SHA-256 hash verification before publication and setting restricted file permissions (mode 0555). - Command Execution Interface: The agent is provided with specific commands via the
justanduvtools to perform cache inspection, pruning, and enforcement. These commands are part of the core functionality for managing the development environment's storage and build artifacts. - Data Ingestion and Integrity: The skill interacts with external metadata from tools like Docker, Tart, and Cargo. To mitigate risks associated with processing this data, the skill mandates the use of strict, frozen Pydantic models with
extra="forbid"to ensure that only expected data structures are processed. - Access Control and Scoping: The skill emphasizes a "One Authority" model where all cache decisions are centralized in a configuration file, and producers are restricted from discovering backend locations or constructing their own paths, which helps maintain clear security boundaries.
Audit Metadata