choosing-tools

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation and does not contain any executable scripts or automated commands.
  • [DATA_EXPOSURE]: In projects/web.md, the instructions suggest that the agent read local documentation from ~/code/void-sdk/void/docs/ and ~/code/void-sdk/void/README.md if the 'Void' framework is selected. This refers to a local development environment path rather than sensitive system files or credentials.
  • [EXTERNAL_DOWNLOADS]: The skill recommends a wide variety of third-party Node.js and Rust packages. The majority of these are well-known, high-quality community tools (e.g., vue, nuxt, tokio, eslint). Some tools like vite-plus and motion-v are less standard, but their inclusion in a recommendation list does not constitute a security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 01:28 PM
Security Audit — agent-trust-hub — choosing-tools