xy-toolchain
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill provides standard documentation for a development toolchain and includes explicit security warnings, such as advising users not to commit
.npmrcfiles containing authentication tokens.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing official XY Labs packages (@xylabs and @xyo-network scopes) and reputable open-source tools (eslint, vitest, typescript, vite). These are legitimate dependencies used according to their intended purpose.\n- [COMMAND_EXECUTION]: The skill instructs the use of toolchain CLI commands likepackage-buildandpackage-lint. These are standard wrappers for build and quality assurance processes within the developer's environment.
Audit Metadata