user-model-builder

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches public content from external sources including Substack, Twitter, and the Wayback Machine using tools like Firecrawl and Jina. These operations are core to the skill's stated purpose of archiving and analyzing published content.
  • [COMMAND_EXECUTION]: The skill executes a local Python validation script (scripts/validate_usermodel.py) using the uv tool. Analysis of the script confirms it is limited to file system read operations, YAML parsing, and text comparison to verify the accuracy of the built models.
  • [DATA_EXFILTRATION]: While the skill aggregates significant amounts of personal information (posts, bios, worldview markers) from the web, the data is stored locally in the user's home directory (~/.claude/userModels/). No evidence was found of the skill sending this aggregated data to unauthorized external endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:38 PM
Security Audit — agent-trust-hub — user-model-builder