clean-system-cache

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes native shell scripts (clean-cache.sh and clean-cache.cmd) to invoke standard cleanup commands for established developer tools, including npm cache clean, uv cache clean, docker builder prune, and pnpm store prune. These operations are well-scoped to the skill's primary purpose of disk maintenance.
  • [SAFE]: The scripts implement robust 'Running Session Protection' by checking active process lists (via pgrep on POSIX and tasklist on Windows) for applications like Photoshop, Figma, and all major web browsers. If a session is detected, the skill skips the cleanup for that specific tool to prevent data corruption or session interruption.
  • [SAFE]: The cleanup logic is strictly targeted at disposable HTTP caches and build artifacts (e.g., Cache_Data, Code Cache, cache2/entries, .crate archives). The implementation explicitly avoids touching sensitive user profile data, including cookies, login credentials, browsing history, and bookmarks.
  • [SAFE]: The skill operates entirely locally using standard system utilities (du, df, find, rm) and does not perform any network operations or external data exfiltration. All directory paths are properly quoted in the scripts to prevent shell injection during path expansion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:27 PM
Security Audit — agent-trust-hub — clean-system-cache