intent-mapper

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (run.sh, sanity.sh) and uses typer for CLI command definition. These are used for standard initialization, sanity checking, and skill execution tasks and do not show signs of arbitrary command injection or privilege escalation.
  • [EXTERNAL_DOWNLOADS]: The pyproject.toml file lists standard dependencies such as unsloth, transformers, and httpx. These are well-known libraries and do not involve unverifiable or risky remote code execution.
  • [DATA_EXPOSURE]: The resolver.py script makes requests to a local service (http://localhost:8601). This is used for internal communication with a memory daemon and does not involve unauthorized data exfiltration or exposure of sensitive credentials.
  • [SAFE]: The skill follows standard security practices for managing internal dependencies and providing evaluation harnesses (eval_resolver.py). No obfuscation, persistence mechanisms, or prompt injection patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — intent-mapper