repo-onboarding-flow

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The repository scaffolding script uses quoted variables for directory creation and file operations, which is a standard practice to prevent path injection.
  • [SAFE]: The skill incorporates security-conscious configurations by including sensitive file patterns (.env, *.secret) in the .gitignore template and integrating the detect-private-key hook in the pre-commit configuration.
  • [EXTERNAL_DOWNLOADS]: The configuration files reference well-known development tools, such as ruff from Astral Software and official pre-commit hooks. These references target established, reputable software maintainers.
  • [SAFE]: The Python functions for repository registration and validation utilize safe parsing methods, such as yaml.safe_load, and perform basic schema validation on the input data.
  • [SAFE]: References to ecosystem components like organvm-engine represent legitimate integration with the vendor's own tools and services, consistent with the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — repo-onboarding-flow