submit-element
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bun runto execute local project scripts and theghCLI to interact with the GitHub API for permission verification. - [EXTERNAL_DOWNLOADS]: It fetches user data and repository collaborator status from official GitHub API endpoints.
- [DATA_EXFILTRATION]: For authorized maintainers, the skill facilitates the upload of preview assets to the vendor's domain (
remotion.media). - [CREDENTIALS_UNSAFE]: The skill checks for the existence of AWS credentials in the environment while explicitly instructing the agent not to print or reveal their values.
- [SAFE]: All external resources and scripts originate from the vendor's infrastructure or trusted services. No signs of obfuscation or malicious patterns were found.
Audit Metadata