pk-analyze

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is strictly read-only and does not possess capabilities to modify the file system or environment.
  • [SAFE]: File access is restricted to local project-specific paths (e.g., .cockpit/, objective.md, plan.md) for the purpose of metric calculation and status reporting. No network operations or credential accesses were found.
  • [SAFE]: The skill processes content from project data and logs. Although this is a data ingestion surface, the skill lacks dangerous capabilities such as shell execution or network writing, which prevents any significant exploitation.
  • Ingestion points: Local files objective.md, plan.md, and the log/ directory.
  • Boundary markers: None present.
  • Capability inventory: Read-only access to specific local files.
  • Sanitization: None present.
  • [NO_CODE]: The skill consists of instructional instructions and does not ship with any code, scripts, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:34 AM
Security Audit — agent-trust-hub — pk-analyze