bulk-import

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves the official Subframe CLI utility from the public package registry. This is a standard and expected behavior for using vendor-provided tools.\n- [COMMAND_EXECUTION]: Shell commands are used to manage local configuration files and run the import utility. These operations are necessary for the skill's stated workflow.\n- [DATA_EXFILTRATION]: The skill transmits design system files and metadata to Subframe's official servers. This is the intended function of the skill and uses the vendor's authenticated infrastructure.\n- [REMOTE_CODE_EXECUTION]: The Subframe CLI is executed through npx to perform the batch import. This process uses official vendor software to process and upload component data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:57 PM
Security Audit — agent-trust-hub — bulk-import