gear

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the use of standard system and DevOps tools for maintenance, including package managers (npm, pnpm, yarn, bun), container platforms (docker, docker-compose), and cloud native tooling (kubectl, helm, terraform, pulumi). These operations are essential to the primary goal of infrastructure and environment optimization.
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to fetch configuration and tools from well-known and reputable services, such as the Bun runtime installation script from its official domain and various GitHub Actions from their official repositories. These downloads align with documented organizational trust policies.
  • [REMOTE_CODE_EXECUTION]: The instructions include patterns for installing development tools via piped shell execution (e.g., Bun installation). As these patterns target recognized and established technology services, they are documented as part of standard setup procedures rather than malicious intent.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external project data including source code, lockfiles, and configuration manifests. While this represents a theoretical attack surface for indirect prompt injection, the skill mitigates this through a structured maintenance workflow (TUNE-TIGHTEN-GREASE-VERIFY) and by enforcing rigorous supply chain security controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — gear