built-in-ai
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/fetch-idls.jsscript fetches Web IDL definitions from the officialwebmachinelearningorganization on GitHub. These downloads target established technical standards repositories and are used to provide the agent with accurate technical signatures. - [COMMAND_EXECUTION]: The package utilizes an npm
postinstallscript to runscripts/install.js. This script synchronizes documentation templates to the user's project root, which is the primary intended function of this package. - [SAFE]: The skill instructions explicitly direct the AI agent to advocate for security best practices, such as using
DOMPurifyto sanitize untrusted LLM outputs before rendering them in a web interface. - [SAFE]: No obfuscation, data exfiltration patterns, or unauthorized privilege escalation attempts were detected. All external resource references are to well-known and trusted technology organizations.
Audit Metadata