developer-tooling

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents standard software engineering workflows, including linter/formatter configurations (Biome, ESLint), build tools (Vite, tsup), and project organization rules.
  • [REMOTE_CODE_EXECUTION]: Mentions of npx openapi-typescript, npx prisma generate, and npx lint-staged are standard developer tool invocations for code generation and pre-commit hooks, not malicious remote code execution.
  • [EXTERNAL_DOWNLOADS]: The skill references official schemas (biomejs.dev) and standard package registries, which are trusted developer resources.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or exfiltration were detected. The proxy configuration in the Vite example targets localhost:8080, which is a standard local development setup.
  • [COMMAND_EXECUTION]: Shell commands provided (biome check, npx, husky) are standard CLI operations for developer environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — developer-tooling