oneshot-websites
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a high-security posture through several design choices:
- Agent Isolation: It requires spawning subagents with no inherited conversation history (
fork_turns: 'none'), preventing context leakage between runs or from the coordinator. - Local-First Default: The skill explicitly prohibits remote publication or writes to services like Vercel, Cloudflare, or GitHub unless the user provides a specific, narrow instruction. It treats ambient tool authentication as a capability, not authorization.
- Provenance and Integrity: It uses a coordinator-owned directory (
.oneshot-provenance) to store immutable records of run identities and prompt digests, ensuring that worker-owned scripts cannot modify their own history or masquerade as successful runs. - Artifact Scanning: The included
validate_catalog.pyscript automatically scans generated artifacts for sensitive files, such as SSH private keys, environment files, and project configuration data, before they are considered valid. - Path Traversal Defenses: The scripts use strict path resolution and child-validation logic to ensure that file operations (such as cleanup of temporary files) are confined to the specific run directory.
Audit Metadata