asset-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: A Python script snippet in SKILL.md demonstrates the use of subprocess.run to call the external texconv utility. The implementation uses list-based argument passing, which is the recommended practice to avoid shell injection vulnerabilities. The tool use is directly aligned with the skill's stated purpose of asset pipeline management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:15 AM
Security Audit — agent-trust-hub — asset-optimization