community-publish

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a security validation module in lib/validate.py which actively prevents the publication of sensitive data. It scans for blocked paths such as .ssh, .aws/credentials, and .env files, and uses regex patterns to detect hardcoded secrets like API keys (OpenAI, Anthropic, GitHub) and private keys.
  • [SAFE]: External network communications are limited to trusted services and vendor infrastructure. The skill interacts with the official GitHub API (api.github.com) and raw content domains (raw.githubusercontent.com) for open-sourcing code, and uses Google Cloud Storage (storage.googleapis.com) for project cover images. All these actions are consistent with the skill's primary purpose of publishing and listing projects.
  • [SAFE]: The fork and install mechanisms in lib/install.py do not perform arbitrary code execution. Instead, they provide structured instructions ('next steps') for the agent to follow, ensuring that project setup remains transparent and subject to agent-level controls.
  • [SAFE]: Environment variable handling is restricted to necessary identifiers (e.g., USER_ID, FLY_MACHINE_ID) and uses standard project configuration logic to identify missing requirements in .env.example files.
  • [SAFE]: No obfuscation, persistence mechanisms, or privilege escalation attempts were detected. The skill uses safe YAML parsing practices (yaml.safe_load) where available.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — community-publish