asset-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no executable scripts or binaries. It consists of markdown documentation, SQL bootstrap/overlay scripts, and Prisma schema fragments intended for reference and implementation within a developer's project.
  • [SAFE]: Command execution is limited to project-local developer tools (e.g., pnpm registry:sync) for the purpose of synchronizing project assets with a database. No unauthorized network operations or exfiltration patterns were detected.
  • [SAFE]: The skill correctly addresses security best practices, such as recommending the removal of script tags from SVG icons and advising against the storage of secrets or raw user content within the registry tables.
  • [SAFE]: Data ingestion surfaces are well-defined (scanning codebase for JSDoc annotations) and intended for metadata extraction. The skill provides clear boundary rules and sanitization guidance to mitigate risks associated with processing project content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:22 AM
Security Audit — agent-trust-hub — asset-weapon