browser-storage-durability-contracts

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill focuses on providing diagnostic checklists and search patterns for IndexedDB and StorageManager APIs, without introducing security risks.
  • [COMMAND_EXECUTION]: The skill recommends using rg (ripgrep) to identify relevant code sections in the local application. These searches are confined to the local filesystem and are standard for code analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external inputs such as project code and PR descriptions, which is an inherent vulnerability surface. Ingestion points: Local source code and user-supplied descriptions of failures. Boundary markers: None specified. Capability inventory: The skill identifies code patterns and provides analysis; it does not request network access or write permissions. Sanitization: No explicit sanitization of input data is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:59 PM
Security Audit — agent-trust-hub — browser-storage-durability-contracts