oneshot-websites

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a high-security posture through several design choices:
  • Agent Isolation: It requires spawning subagents with no inherited conversation history (fork_turns: 'none'), preventing context leakage between runs or from the coordinator.
  • Local-First Default: The skill explicitly prohibits remote publication or writes to services like Vercel, Cloudflare, or GitHub unless the user provides a specific, narrow instruction. It treats ambient tool authentication as a capability, not authorization.
  • Provenance and Integrity: It uses a coordinator-owned directory (.oneshot-provenance) to store immutable records of run identities and prompt digests, ensuring that worker-owned scripts cannot modify their own history or masquerade as successful runs.
  • Artifact Scanning: The included validate_catalog.py script automatically scans generated artifacts for sensitive files, such as SSH private keys, environment files, and project configuration data, before they are considered valid.
  • Path Traversal Defenses: The scripts use strict path resolution and child-validation logic to ensure that file operations (such as cleanup of temporary files) are confined to the specific run directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 01:19 PM
Security Audit — agent-trust-hub — oneshot-websites