built-in-ai

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/fetch-idls.js script fetches Web IDL definitions from the official webmachinelearning organization on GitHub. These downloads target established technical standards repositories and are used to provide the agent with accurate technical signatures.
  • [COMMAND_EXECUTION]: The package utilizes an npm postinstall script to run scripts/install.js. This script synchronizes documentation templates to the user's project root, which is the primary intended function of this package.
  • [SAFE]: The skill instructions explicitly direct the AI agent to advocate for security best practices, such as using DOMPurify to sanitize untrusted LLM outputs before rendering them in a web interface.
  • [SAFE]: No obfuscation, data exfiltration patterns, or unauthorized privilege escalation attempts were detected. All external resource references are to well-known and trusted technology organizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 02:15 AM