starwind-pro

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows established security best practices by instructing the agent to never hardcode, expose, or prompt the user for license keys in plaintext, recommending the use of environment variables (.env.local) instead.
  • [COMMAND_EXECUTION]: The skill uses the starwind CLI for initialization and component installation. These commands are explicitly restricted in the YAML frontmatter to prevent arbitrary command execution, ensuring that only the vendor's tool can be invoked.
  • [EXTERNAL_DOWNLOADS]: The skill references component registries and documentation at pro.starwind.dev. These are official resources belonging to the vendor (starwind-ui) and are consistent with the skill's stated purpose.
  • [NO_CODE]: The skill does not bundle any hidden scripts, executables, or obfuscated payloads. All provided instructions and references are in plain-text markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 06:34 AM
Security Audit — agent-trust-hub — starwind-pro