service-worker

Pass

Audited by Gen Agent Trust Hub on Feb 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Found in SKILL.md and references/push-notifications.md.
  • The SKILL.md file contains instructions to execute pnpm dlx skills add oakoss/agent-skills to delegate tasks to related local-first and database skills. These commands target the vendor's own infrastructure and are used for legitimate functionality extension.
  • The references/push-notifications.md file mentions the use of npx web-push for generating VAPID keys, which is a standard development tool for push notification security.
  • [EXTERNAL_DOWNLOADS]: Found in SKILL.md. The delegation instructions involve downloading additional skill configurations from the author's official repository (oakoss/agent-skills). This is a transparent operation for cross-skill integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 24, 2026, 08:36 PM