collector-diagnostics

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes bunx usagemax@latest to fetch the diagnostic utility from the npm registry. This is the intended behavior for verifying the status of UsageMax collector credentials.
  • [REMOTE_CODE_EXECUTION]: The usagemax package downloaded from the npm registry is executed to perform device-binding checks and telemetry tests.
  • [DATA_EXFILTRATION]: The instructions describe a telemetry test targeting https://usagemax.com/api/v1/telemetry/llm. The skill includes specific security guardrails to ensure that no sensitive information—including prompts, source code, file paths, or credentials—is included in the outgoing request.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:14 PM
Security Audit — agent-trust-hub — collector-diagnostics