hz-api-upgrade

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill provides legitimate developer documentation for SDK migration and uses official vendor tools.
  • [REMOTE_CODE_EXECUTION]: The skill recommends using npx -y @meta-quest/hzdb, which downloads and executes the vendor's command-line tool. This is a standard deployment method for the tool and is considered safe within the context of the 'meta-quest' author.
  • [COMMAND_EXECUTION]: The skill uses standard shell utilities like grep and git, along with the project-specific hzdb tool, to perform code searches, build operations, and device deployments. These commands are restricted to the intended purpose of application development and maintenance.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 11:02 AM
Security Audit — agent-trust-hub — hz-api-upgrade