web-artifacts-builder

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of a wide range of standard Node.js packages from the official npm registry using npm and pnpm. These include well-known libraries such as React, Vite, Tailwind CSS, and various UI component libraries like Radix UI.
  • [COMMAND_EXECUTION]: Automated shell scripts (scripts/init-artifact.sh and scripts/bundle-artifact.sh) are provided to manage project scaffolding and asset bundling. These scripts execute common development commands using standard binaries like pnpm, node, tar, and sed to configure the local workspace.
  • [EXTERNAL_DOWNLOADS]: During initialization, the skill extracts a local component archive (shadcn-components.tar.gz) into the project's source tree. This is a standard asset-loading mechanism for this skill's scaffolding process.
  • [SAFE]: No malicious behaviors, including data exfiltration, hardcoded credentials, obfuscation, or persistence mechanisms, were detected in the provided files. The skill's operations are consistent with its documented purpose of building frontend artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 12:59 AM
Security Audit — agent-trust-hub — web-artifacts-builder