handshake
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts with local files (MEMORY.md, user_.md, project_.md) to manage user preferences and project metadata. This is the primary function of the skill and uses standard platform memory conventions for persistence.
- [SAFE]: Instructions include a "Hard never-ask list" that explicitly prohibits the agent from collecting or storing sensitive personal information (PII), such as government identifiers, financial details, health information, and passwords, which mitigates data exposure risks.
- [SAFE]: External URL references and installation instructions point to the author's official GitHub repository (sorawit-w/agent-skills) for assets and plugin distribution, which are categorized as legitimate vendor-owned resources.
Audit Metadata