skills/j4rk0r/claude-skills/milestone/Gen Agent Trust Hub

milestone

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute a bundled shell script (references/milestone-new-session.sh) for session management. This script uses python3 to parse metadata from local milestone files and osascript on macOS to automate the creation of new terminal windows (iTerm2 or Terminal.app) for fresh agent sessions.\n- [EXTERNAL_DOWNLOADS]: The skill documentation (README.md) mentions installation via npx, which is a standard package runner for Node.js-based tools and does not represent a security risk in this context.\n- [DATA_EXFILTRATION]: No suspicious network activity or unauthorized data transfer patterns were detected. The skill reads and writes project data to the local .milestones/ directory and a project-specific cache located in ~/.claude/projects/, which is necessary for its stated function of maintaining cross-session context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 07:17 PM
Security Audit — agent-trust-hub — milestone