skills/joker-ye/skills/node-dev/Gen Agent Trust Hub

node-dev

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends several development scripts and tools that execute system commands for project management.
  • Evidence: The configuration in SKILL.md uses pnpm and npx for dependency management and git hooks.
  • Evidence: The alias.ts script template in references/monorepo.md uses Node.js fs modules to read and write to tsconfig.alias.json for managing path aliases.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources for CI/CD automation and configuration.
  • Evidence: references/setting-up.md recommends using GitHub Actions workflows from the sxzz/workflows repository.
  • [SAFE]: The skill integrates several security-enhancing practices.
  • Evidence: The .gitignore template in references/setting-up.md correctly excludes sensitive files like environment variables (.env) and private keys (*.pem).
  • Evidence: The suggested pre-commit hook in SKILL.md includes the --ignore-scripts flag when running pnpm install, preventing the execution of potentially malicious scripts during the installation phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 10:44 AM
Security Audit — agent-trust-hub — node-dev