skills/jsmastery-pro/pilot/sync/Gen Agent Trust Hub

sync

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses git commands (git fetch, git rev-list, git rev-parse, git diff, git ls-files) to analyze the current repository state and determine what source files have changed. These are standard operations for development workflows and are restricted to repository metadata and diffing.
  • [REMOTE_CODE_EXECUTION]: While the skill mentions npx skills add, this is documented as a manual confirmation step for the user to install relevant skills for newly detected tools, rather than an automated execution of untrusted remote code.
  • [DATA_EXPOSURE]: The skill explicitly instructs the agent to drop sensitive configuration and lock files from the change set analysis, focusing only on source code and dependency manifests to drive documentation updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 06:04 PM
Security Audit — agent-trust-hub — sync