strapi-product-builder

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill operates as a product design assistant, using a multi-stage interview to help users define project requirements.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation from official and well-known sources, including docs.strapi.io, nextjs.org, tanstack.com, and astro.build. These are legitimate resources used to ground the agent's technical recommendations.
  • [COMMAND_EXECUTION]: The skill provides templates for project initialization commands (e.g., npx create-strapi-app, npm install). These are intended for the user or a coding agent to execute in a separate development environment and are not executed by the skill itself during its operation.
  • [SAFE]: The skill implements security best practices in its technical recommendations, such as advising the use of environment variables for secrets, implementing least-privilege access for MCP tokens, and suggesting proper sanitization of user-owned content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 08:31 AM
Security Audit — agent-trust-hub — strapi-product-builder