picoclaw-self-pen-testing
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Node.js scripts to read and analyze local security profiles. These scripts (
scripts/self_pen_test.mjs) are executed on-demand by the operator to generate findings based on local JSON data. - [SAFE]: The skill's primary function is a read-only audit. It includes robust documentation for manual verification of release artifacts using GPG/OpenSSL, promoting secure supply chain practices for the operator. The file operations are limited to reading specific configuration files provided via CLI arguments, and no network egress or data exfiltration patterns were detected.
Audit Metadata