strapi-product-builder
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill operates as a product design assistant, using a multi-stage interview to help users define project requirements.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation from official and well-known sources, including
docs.strapi.io,nextjs.org,tanstack.com, andastro.build. These are legitimate resources used to ground the agent's technical recommendations. - [COMMAND_EXECUTION]: The skill provides templates for project initialization commands (e.g.,
npx create-strapi-app,npm install). These are intended for the user or a coding agent to execute in a separate development environment and are not executed by the skill itself during its operation. - [SAFE]: The skill implements security best practices in its technical recommendations, such as advising the use of environment variables for secrets, implementing least-privilege access for MCP tokens, and suggesting proper sanitization of user-owned content.
Audit Metadata