skills/softspark/ai-toolkit/explore/Gen Agent Trust Hub

explore

Warn

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection (!find ...) in the SKILL.md file to list configuration files at the moment the skill is loaded by the agent. This execution happens before user interaction.
  • [COMMAND_EXECUTION]: The visualize.py script uses webbrowser.open() to automatically trigger the system's default browser to open a generated file. While the script itself is a local file-system scanner, the automated browser opening is an unexpected side effect for a background agent skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 06:06 AM
Security Audit — agent-trust-hub — explore