repo-onboarding-flow
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The repository scaffolding script uses quoted variables for directory creation and file operations, which is a standard practice to prevent path injection.
- [SAFE]: The skill incorporates security-conscious configurations by including sensitive file patterns (
.env,*.secret) in the.gitignoretemplate and integrating thedetect-private-keyhook in the pre-commit configuration. - [EXTERNAL_DOWNLOADS]: The configuration files reference well-known development tools, such as
rufffrom Astral Software and officialpre-commithooks. These references target established, reputable software maintainers. - [SAFE]: The Python functions for repository registration and validation utilize safe parsing methods, such as
yaml.safe_load, and perform basic schema validation on the input data. - [SAFE]: References to ecosystem components like
organvm-enginerepresent legitimate integration with the vendor's own tools and services, consistent with the stated purpose of the skill.
Audit Metadata