skills/solpbc/vit/using-vit/Gen Agent Trust Hub

using-vit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements clear 'agent' vs 'human' boundaries. Sensitive commands such as vit login, vit adopt, and vit vet (manual trust assignment) are explicitly restricted from agent execution to prevent unauthorized authentication or autonomous trust escalation.- [SAFE]: All external interactions target the ATProto network or the official explore.v-it.org index, which are documented as the primary purpose of the tool. Use of these well-known services follows the intended skill workflow.- [SAFE]: Command execution patterns (e.g., vit ship, vit skim) are standard CLI operations within a controlled social software environment and do not involve shell injection or arbitrary command execution from untrusted sources.- [SAFE]: Data handling is restricted to the .vit/ directory for configuration and following lists, adhering to standard local state management practices without accessing sensitive system files or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:41 PM
Security Audit — agent-trust-hub — using-vit