process-automated-builder
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npm execto download and run the@tiangong-lca/cli@latestpackage from the npm registry at runtime. This is an official resource from the skill vendor and is used to provide the core functionality of the skill.- [COMMAND_EXECUTION]: The scriptscripts/run-process-automated-builder.mjsinvokes thetiangongCLI tool via shell commands. It manages argument forwarding and handles temporary files for inputs such as flow definitions and requests.- [DATA_EXFILTRATION]: Analysis of the execution flow shows that the skill reads local configuration files and reference data to produce artifacts in user-defined directories. No unauthorized data transmission to external servers was detected.
Audit Metadata