fixture-tricky

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill behaves exactly as described in its documentation.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes standard Python dependencies (pymupdf, reportlab, typer) which are resolved through the official PyPI registry using the uv package manager. These are well-known libraries for PDF manipulation and CLI development.
  • [COMMAND_EXECUTION]: The skill uses uv run to execute its generation scripts and writes PDF files to the local file system. These actions are within the scope of the assigned Bash and Write tool permissions and are necessary for the skill's function.
  • [OBFUSCATION]: While the skill contains homoglyphs and invisible characters (e.g., zero-width spaces) in gen_tricks_core.py, these are explicitly implemented as data samples for testing PDF extractors, rather than techniques used to hide malicious logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:16 AM
Security Audit — agent-trust-hub — fixture-tricky