build-runtype-app
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents the deployment lifecycle for the Runtype platform, authored by runtypelabs. All external references point to the vendor's official infrastructure (runtype.com and runtype.run).
- [SAFE]: External dependencies are limited to the official Runtype MCP server (api.runtype.com), which is a verified vendor resource required for the skill's stated purpose of application deployment.
- [SAFE]: The instructions explicitly discourage security anti-patterns, such as hardcoding credentials, and instead recommend using the platform's secure boot configuration (window.RUNTYPE_APP) for managing client tokens.
- [SAFE]: The skill highlights security constraints like Content Security Policy (CSP) and manifest-based capability scoping to ensure apps operate within a restricted environment.
Audit Metadata