license-compliance
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for the legitimate purpose of auditing package licenses and uses the
mcp__very-good-cli__packages_check_licensestool, which is a resource provided by the author (VeryGoodOpenSource). - [SAFE]: It contains explicit safety instructions to prevent the agent from certifying project compliance without a verifiable scan, specifically instructing the agent to withhold verdicts when only partial information (like a dependency list) is available.
- [SAFE]: The reporting phase uses a fixed Markdown template, which ensures consistent output and prevents the agent from deviating into conversational prose that might be influenced by malicious content in the scanned data.
- [SAFE]: No patterns of data exfiltration, hardcoded credentials, obfuscation, or unauthorized command execution were detected.
Audit Metadata