building-glamorous-tuis

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install tools and libraries such as gum, vhs, mods, and bubbletea using 'brew install' and 'go get'. These resources are hosted by the charmbracelet organization, which is a recognized and well-known developer of terminal utilities.\n- [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands and scripts. These are presented as educational recipes for creating user interfaces, such as using 'gum confirm' to gate destructive actions like 'rm -rf', demonstrating safe coding practices in tool design.\n- [DATA_EXFILTRATION]: Infrastructure guides for 'wish' (an SSH server library) and 'melt' (an SSH key backup tool) describe accessing configuration files and keys in the ~/.ssh/ directory. Additionally, 'pop' is documented as a tool for sending emails. This behavior is consistent with the primary purpose of managing SSH-accessible applications, backing up keys, and terminal-based communication.\n- [CREDENTIALS_UNSAFE]: An example command for the 'skate' utility in 'references/infrastructure.md' uses a placeholder string 'sk-1234567890' to demonstrate setting a key. This is a generic example value used for documentation purposes and does not represent an actual credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 02:25 AM