embedding-ft
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npm execto download and run the@tiangong-lca/clipackage from the NPM registry at runtime. This is a vendor-owned resource required for the skill's operations. - [COMMAND_EXECUTION]: The script
scripts/run-embedding-ft.mjsexecutes shell commands to invoke thetiangongCLI for processing embedding jobs. - [DATA_EXFILTRATION]: The skill sends data to a Supabase edge function endpoint. This is the intended network operation for communicating with the embedding worker backend.
Audit Metadata