@tank/bundle-creator
Pass
Audited by Gen Agent Trust Hub on May 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as an educational resource and reference guide for a specific package format (Tank bundles). It does not contain executable scripts or perform network operations outside of referencing the author's own repository.
- [EXTERNAL_DOWNLOADS]: References the author's official GitHub repository (
github.com/tankpkg/packages) for registry and contribution standards, which is consistent with the skill's stated purpose. - [COMMAND_EXECUTION]: The documentation describes the use of JavaScript/TypeScript hook handlers and subprocess execution for bundle functionality, but the skill itself does not implement these capabilities and its own configuration explicitly disables subprocesses.
- [DATA_EXPOSURE]: The skill's manifest (
tank.json) requests read access to all project files (**/*). This is an expected permission for a developer tool designed to assist in creating and organizing project-wide package bundles.
Audit Metadata