ultracite

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bunx, npx, pnpx, and yarn dlx to execute its command-line interface (ultracite). This is a standard practice for running Node.js-based tools without local installation.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. All execution is scoped to the ultracite package, which is identified as the vendor's primary tool.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or secrets were detected.
  • [DATA_EXFILTRATION]: No network operations or unauthorized data access patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:31 PM
Security Audit — agent-trust-hub — ultracite