axhub-commentary-client

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious scripts, obfuscation, or unauthorized network operations were detected. The skill consists entirely of instructional markdown files and code templates for developer workflows.\n- [DATA_EXPOSURE]: The skill instructs the agent to expose local file system metadata, including absolute paths (e.g., projectPath, filePath), to the browser's global window object (window.__COMMENTARY_HOST__). While this is a form of information disclosure, it is the intended functional requirement for the Axhub Commentary tool to link web previews to local source code during development.\n- [NO_CODE]: The skill provides documentation and instructions for the agent to assist with project configuration but does not package any executable code, scripts, or binaries of its own.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 10:29 AM
Security Audit — agent-trust-hub — axhub-commentary-client