supply-chain-risk-auditor
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions specify the use of the
gh(GitHub CLI) tool to perform lookups for repository metadata, such as star counts, issue counts, and security contacts. This command execution is a core part of the skill's intended functionality to verify dependency health through a well-known service. - [SAFE]: The skill performs file operations strictly within a local workspace directory (
.supply-chain-risk-auditor) and generates a report using a local template. There are no patterns suggesting data exfiltration, credential theft, or unauthorized persistence.
Audit Metadata