kw-stack-audit

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs localized, read-only analysis of project configuration files (e.g., tsconfig.json, package.json) and source code to identify potential issues.- [SAFE]: Modification of project files or installation of recommended development tools like Biome is strictly guarded by user confirmation steps, including displaying diffs before application.- [SAFE]: The identification of hardcoded secrets and URLs in references/security-constants.md is a security feature designed to assist the user in improving their local environment security, with no evidence of data exfiltration.- [SAFE]: Commands executed by the skill, such as npx tsc --noEmit, are standard development workflows used to validate type safety and do not involve remote code execution from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 11:24 AM