defold-skill-maintain
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a Python script (
scripts/fetch_proto.py) that fetches the Defold SDK from the official Defold repository on GitHub (github.com/defold/defold). This is a well-known and official source for the software.\n- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute a local Python script to update its internal assets. The script includes security best practices, such as a check to prevent zip-slip vulnerabilities during the extraction of the SDK archive.\n- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill's behavior is consistent with its stated purpose of synchronizing documentation and schemas from authoritative sources.
Audit Metadata