community-publish
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a security validation module in
lib/validate.pywhich actively prevents the publication of sensitive data. It scans for blocked paths such as.ssh,.aws/credentials, and.envfiles, and uses regex patterns to detect hardcoded secrets like API keys (OpenAI, Anthropic, GitHub) and private keys. - [SAFE]: External network communications are limited to trusted services and vendor infrastructure. The skill interacts with the official GitHub API (
api.github.com) and raw content domains (raw.githubusercontent.com) for open-sourcing code, and uses Google Cloud Storage (storage.googleapis.com) for project cover images. All these actions are consistent with the skill's primary purpose of publishing and listing projects. - [SAFE]: The
forkandinstallmechanisms inlib/install.pydo not perform arbitrary code execution. Instead, they provide structured instructions ('next steps') for the agent to follow, ensuring that project setup remains transparent and subject to agent-level controls. - [SAFE]: Environment variable handling is restricted to necessary identifiers (e.g.,
USER_ID,FLY_MACHINE_ID) and uses standard project configuration logic to identify missing requirements in.env.examplefiles. - [SAFE]: No obfuscation, persistence mechanisms, or privilege escalation attempts were detected. The skill uses safe YAML parsing practices (
yaml.safe_load) where available.
Audit Metadata