browser-native
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs local filesystem operations, reading package.json files to provide modernization recommendations without accessing sensitive user data.\n- [SAFE]: No network activity was detected in the source code; the tool functions entirely offline and does not include exfiltration logic.\n- [SAFE]: The skill relies exclusively on Node.js built-in modules such as node:fs and node:path, and does not include any third-party dependencies.\n- [SAFE]: There are no instances of dynamic code execution or remote script fetching in the implementation.\n- [SAFE]: Input from package.json files is validated against a static internal database of known packages, preventing the reflection of arbitrary untrusted content into generated reports.
Audit Metadata