skills/magic5644/skills/graph-it-live/Gen Agent Trust Hub

graph-it-live

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @magic5644/graph-it-live npm package or run it via npx. This is a vendor-owned resource from the skill author used to provide the core analysis functionality.
  • [COMMAND_EXECUTION]: The skill utilizes several CLI commands (e.g., graph-it scan, graph-it trace, graph-it summary) to index and analyze the user's workspace. These operations are local and consistent with the skill's stated purpose of dependency intelligence.
  • [REMOTE_CODE_EXECUTION]: Provides an update command which is a standard feature for maintaining the CLI tool's version. No unverified or suspicious remote execution patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 04:00 PM
Security Audit — agent-trust-hub — graph-it-live