hz-api-upgrade
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill provides legitimate developer documentation for SDK migration and uses official vendor tools.
- [REMOTE_CODE_EXECUTION]: The skill recommends using
npx -y @meta-quest/hzdb, which downloads and executes the vendor's command-line tool. This is a standard deployment method for the tool and is considered safe within the context of the 'meta-quest' author. - [COMMAND_EXECUTION]: The skill uses standard shell utilities like
grepandgit, along with the project-specifichzdbtool, to perform code searches, build operations, and device deployments. These commands are restricted to the intended purpose of application development and maintenance.
Audit Metadata