flag-metadata

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for administrative management of GrowthBook feature flags, including updating descriptions, owners, projects, and tags.
  • [COMMAND_EXECUTION]: The skill uses a bundled script ${CLAUDE_PLUGIN_ROOT}/scripts/gb-call to perform REST API operations against GrowthBook's official endpoints. This execution is limited by the platform's allowed-tools configuration.
  • [CREDENTIALS_UNSAFE]: The skill references the use of an API key (GB_API_KEY) stored in standard environment variables or a local configuration file (~/.config/growthbook/.env), which follows established best practices for secret management for this service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:27 PM
Security Audit — agent-trust-hub — flag-metadata