fixture-tricky
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill behaves exactly as described in its documentation.
- [EXTERNAL_DOWNLOADS]: The skill utilizes standard Python dependencies (
pymupdf,reportlab,typer) which are resolved through the official PyPI registry using theuvpackage manager. These are well-known libraries for PDF manipulation and CLI development. - [COMMAND_EXECUTION]: The skill uses
uv runto execute its generation scripts and writes PDF files to the local file system. These actions are within the scope of the assignedBashandWritetool permissions and are necessary for the skill's function. - [OBFUSCATION]: While the skill contains homoglyphs and invisible characters (e.g., zero-width spaces) in
gen_tricks_core.py, these are explicitly implemented as data samples for testing PDF extractors, rather than techniques used to hide malicious logic.
Audit Metadata