migrate

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to guide the user through a migration process using official vendor tools and patterns. It does not perform any autonomous destructive actions.
  • [EXTERNAL_DOWNLOADS]: The skill refers to official LaunchDarkly SDKs for Python, Node.js, and Go, as well as provider-specific helpers for OpenAI, LangChain, and Vercel. These are legitimate resources provided by the vendor (launchdarkly) or well-known ecosystems.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a 'Stage 1 Audit' phase where it scans the user's repository for hardcoded prompts. To mitigate risks associated with processing potentially untrusted content, the skill uses a strictly controlled confirmation loop, requiring the user to provide specific input tokens ('confirm', 'add', 'fix', 'stop') before moving beyond the read-only phase.
  • [COMMAND_EXECUTION]: The skill documentation provides command-line examples for the user to execute (e.g., using curl for API calls or package managers for installations). These are educational and intended for the user, not for silent execution by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:10 PM
Security Audit — agent-trust-hub — migrate