skills/nubjs/nub/soak/Gen Agent Trust Hub

soak

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines several commands to be executed via pnpm, such as soak, soak:fix, and deps:update. These commands invoke scripts located within the repository's scripts/soak/ directory. It also mentions the use of cargo +nightly update for specific dependency maintenance tasks.
  • [DYNAMIC_EXECUTION]: The operational logic for soak window management is implemented in TypeScript (.mts) scripts within the scripts/soak/ directory, which are executed during the maintenance process.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of external tools via the tools:install command. The instructions specify that these tools are SRI-pinned (Subresource Integrity) in external-tools.json, which is a security best practice to ensure the integrity of downloaded binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:25 PM
Security Audit — agent-trust-hub — soak