Run independent multi-agent build and review flows with OPC

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing an external Node.js package (@touchskyer/opc) and cloning a repository from GitHub (iamtouchskyer/opc). These resources originate from an individual publisher rather than a verified organization.\n- [REMOTE_CODE_EXECUTION]: The package installation includes a post-installation script that automatically copies files to the user's home directory (~/.claude/skills/opc/). Such automated scripts can execute arbitrary code during the installation process.\n- [METADATA_POISONING]: The skill metadata includes a 'verification' field asserting that the content has been 'security_reviewed'. Users should ignore this claim as it is self-reported and cannot be independently confirmed within the skill context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:22 AM
Security Audit — agent-trust-hub — Run independent multi-agent build and review flows with OPC