astrowind

Warn

Audited by Gen Agent Trust Hub on Feb 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • EXTERNAL_DOWNLOADS (MEDIUM): The skill performs a git clone from https://github.com/Eng0AI/astrowind-template.git. The repository owner is not on the trusted sources list, posing a risk of downloading unverified code.\n- REMOTE_CODE_EXECUTION (MEDIUM): After cloning, the skill runs npm install and npm run build. This executes scripts (such as postinstall or build scripts) defined in the external repository, allowing for arbitrary code execution from an untrusted source.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 21, 2026, 02:25 PM