achievements

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a non-executable instruction set that gamifies the coding experience. It does not contain any commands for network exfiltration, credential theft, or unauthorized system access.
  • [DATA_EXPOSURE]: The system records progress and achievement history in local files located at ~/.claude/achievements.json and ~/.claude/team-leaderboard.json. This usage of persistent storage is limited to its own configuration and state management.
  • [COMMAND_EXECUTION]: Integration points mention hooks like achievement-tracker.ts and canavar-cross-review, which are part of the developer's local environment or the vendor's ecosystem for monitoring tool usage. No suspicious or arbitrary shell commands were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 05:43 PM
Security Audit — agent-trust-hub — achievements