craft-site

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents architectural patterns for Craft CMS 5, promoting best practices such as atomic design and the use of environment variables for secret management (e.g., in the Amazon SES and Blitz plugin references).
  • [COMMAND_EXECUTION]: Provides instructions for using standard development CLI tools including DDEV, Composer, and the Craft CMS CLI to manage project environments, dependencies, and configurations.
  • [EXTERNAL_DOWNLOADS]: References external resources and scripts from well-known and trusted providers for analytics, consent management, and asset delivery, such as Google (GTM, Fonts), UserCentrics, CookieBot, Fathom, and Plausible.
  • [DATA_EXFILTRATION]: Documents standard methods for integrating with third-party services like n8n and Google Tag Manager. These integrations use standard API and webhook patterns for data handling.
  • [SAFE]: Includes specific guidance on security auditing through the use of the Sherlock plugin, which scans for HTTP header protections, file permissions, and CMS configuration vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 06:36 AM
Security Audit — agent-trust-hub — craft-site