foundation

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill functions as a security policy, enforcing 'guarded destruction' through the use of safe primitives like skillkit.safe_remove which prevents directory traversal and recursive deletion outside of defined roots.
  • [COMMAND_EXECUTION]: The documentation references the use of internal repository tools and scripts, such as skill-lint and vault.sh, for validation and context retrieval. These tools are part of the vendor's provided infrastructure.
  • [SAFE]: The 'second-brain protocol' describes a mechanism for retrieval-augmented generation (RAG) using a local vault. This is a standard context-enrichment pattern and does not involve unauthorized network access or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — foundation