project-migration

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard development toolchain commands, including git for version control, uv for Python packages, pnpm for Node.js modules, apm for agent skills, and mise for runtime management.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes existing project configuration files, such as package.json and pyproject.toml, to generate migration plans. This potential attack surface is mitigated by instructions requiring the agent to present diffs and obtain explicit user confirmation before modifying or deleting any files.
  • [EXTERNAL_DOWNLOADS]: The workflow involves fetching project blueprints and skill dependencies from the vendor's own repositories (loxosceles/project-blueprints and loxosceles/ai-dev). These operations are consistent with the skill's primary purpose and use vendor-owned resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:58 AM
Security Audit — agent-trust-hub — project-migration