xy-toolchain

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill provides standard documentation for a development toolchain and includes explicit security warnings, such as advising users not to commit .npmrc files containing authentication tokens.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing official XY Labs packages (@xylabs and @xyo-network scopes) and reputable open-source tools (eslint, vitest, typescript, vite). These are legitimate dependencies used according to their intended purpose.\n- [COMMAND_EXECUTION]: The skill instructs the use of toolchain CLI commands like package-build and package-lint. These are standard wrappers for build and quality assurance processes within the developer's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 05:39 AM
Security Audit — agent-trust-hub — xy-toolchain