visual-companion

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The reference files references/program.md and references/copilot_proposer_prompt.md contain instructions and Python snippets for a local optimization loop. These commands are used to evaluate the skill's trigger accuracy and manage version control via git within the development environment.
  • [EXTERNAL_DOWNLOADS]: All dependencies and script references (e.g., the evaluate.py script) point to local relative paths within the plugin directory structure. No remote URLs or external code downloads are utilized.
  • [DATA_EXFILTRATION]: The skill reads from local discovery plans and writes confirmed layout directions to the local file system. It does not perform network operations or access sensitive credentials, and the data handling is confined to the specific project directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:07 PM
Security Audit — agent-trust-hub — visual-companion