process-automated-builder

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npm exec to download and run the @tiangong-lca/cli@latest package from the npm registry at runtime. This is an official resource from the skill vendor and is used to provide the core functionality of the skill.- [COMMAND_EXECUTION]: The script scripts/run-process-automated-builder.mjs invokes the tiangong CLI tool via shell commands. It manages argument forwarding and handles temporary files for inputs such as flow definitions and requests.- [DATA_EXFILTRATION]: Analysis of the execution flow shows that the skill reads local configuration files and reference data to produce artifacts in user-defined directories. No unauthorized data transmission to external servers was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 06:57 AM
Security Audit — agent-trust-hub — process-automated-builder