puck
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate integration guidance for the Puck editor with no evidence of malicious intent or hidden behaviors.\n- [CREDENTIALS_UNSAFE]: Correctly identifies the sensitivity of the
PUCK_API_KEYand instructs the user to use.env.localfor storage, preventing accidental exposure in logs or chat history.\n- [EXTERNAL_DOWNLOADS]: Documentation and package metadata are retrieved exclusively from 'puckeditor.com', ensuring that all external data comes from the official vendor source.\n- [COMMAND_EXECUTION]: Uses standard NPM commands through the Bash tool to verify package versions and visibility, restricted to the@puckeditorscope.\n- [DATA_EXFILTRATION]: Network operations are purpose-built for documentation fetching and communication with the documented Puck Cloud API; no sensitive user data is targeted for exfiltration.
Audit Metadata