svelte-code-writer

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the @sveltejs/mcp package from the public npm registry via npx. This package is maintained by the official Svelte organization, which is a well-known and trusted entity in the web development community.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of CLI commands to list documentation sections and analyze Svelte components. It includes specific safety instructions for the agent to escape shell characters (e.g., escaping $ as \$) when passing code as arguments to the svelte-autofixer tool to prevent unintended shell substitution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 02:47 AM
Security Audit — agent-trust-hub — svelte-code-writer