@tank/bundle-creator

Pass

Audited by Gen Agent Trust Hub on May 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as an educational resource and reference guide for a specific package format (Tank bundles). It does not contain executable scripts or perform network operations outside of referencing the author's own repository.
  • [EXTERNAL_DOWNLOADS]: References the author's official GitHub repository (github.com/tankpkg/packages) for registry and contribution standards, which is consistent with the skill's stated purpose.
  • [COMMAND_EXECUTION]: The documentation describes the use of JavaScript/TypeScript hook handlers and subprocess execution for bundle functionality, but the skill itself does not implement these capabilities and its own configuration explicitly disables subprocesses.
  • [DATA_EXPOSURE]: The skill's manifest (tank.json) requests read access to all project files (**/*). This is an expected permission for a developer tool designed to assist in creating and organizing project-wide package bundles.
Audit Metadata
Risk Level
SAFE
Analyzed
May 31, 2026, 11:04 PM
Security Audit — agent-trust-hub — @tank/bundle-creator