skills/puckeditor/skills/puck/Gen Agent Trust Hub

puck

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate integration guidance for the Puck editor with no evidence of malicious intent or hidden behaviors.\n- [CREDENTIALS_UNSAFE]: Correctly identifies the sensitivity of the PUCK_API_KEY and instructs the user to use .env.local for storage, preventing accidental exposure in logs or chat history.\n- [EXTERNAL_DOWNLOADS]: Documentation and package metadata are retrieved exclusively from 'puckeditor.com', ensuring that all external data comes from the official vendor source.\n- [COMMAND_EXECUTION]: Uses standard NPM commands through the Bash tool to verify package versions and visibility, restricted to the @puckeditor scope.\n- [DATA_EXFILTRATION]: Network operations are purpose-built for documentation fetching and communication with the documented Puck Cloud API; no sensitive user data is targeted for exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 03:43 PM
Security Audit — agent-trust-hub — puck