cocowatch

Pass

Audited by Gen Agent Trust Hub on May 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a purely observational telemetry layer. It tracks how users interact with other tools (CocoHarvest, SecondEye) without interfering with the primary workflow.
  • [COMMAND_EXECUTION]: The skill instructions include writing session data to .cocoplus/lifecycle/cocowatch-session.md. This is used for logging purposes and the skill explicitly requests that this file be excluded from version control to maintain ephemeral session state.
  • [DATA_EXFILTRATION]: No network operations or external data transmissions were identified. All recorded engagement signals are stored locally on the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
May 29, 2026, 07:40 AM
Security Audit — agent-trust-hub — cocowatch