magic-workspace-init

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python code to execute package installation via pip using subprocess.run. This is restricted to a predefined list of standard data science libraries and is executed using the system's current Python interpreter to maintain environment isolation.
  • [EXTERNAL_DOWNLOADS]: The skill automates the installation of common, verifiable Python packages such as pandas, numpy, and scipy from the standard Python Package Index (PyPI). It also includes the data-designer package, which is a recognized vendor resource for this skill.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for the user to configure LLM API keys. It emphasizes safe practices by instructing users to set environment variables in their shell profiles instead of hardcoding credentials or having the skill automatically generate potentially sensitive .env files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 11:49 AM
Security Audit — agent-trust-hub — magic-workspace-init