mastra
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for project management and environment inspection. These include 'ls' to check for installed packages, 'grep' and 'cat' to read local documentation within 'node_modules', and 'npm'/'npx' for dependency installation and running development servers. These commands are directly aligned with the skill's primary purpose of Mastra development.
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and framework updates from well-known official sources, specifically 'https://mastra.ai' and its subpaths. These operations are used to ensure the agent uses the most current API signatures and patterns, which is a standard practice for rapidly evolving frameworks.
- [DATA_EXPOSURE]: The documentation provides guidance on configuring environment variables (e.g., '.env' files) for API keys and database connection strings. Following standard security practices, the skill recommends using 'process.env' rather than hardcoding secrets, which is considered safe configuration management.
Audit Metadata