graphite-cli

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, composed of Markdown guides (SKILL.md, graphite_cli_guide.md, diffstackflow.md). It contains no executable scripts (e.g., .sh, .py, .js) or binaries that could perform automated actions on the user's system.
  • [EXTERNAL_DOWNLOADS]: The reference material includes standard installation instructions for the Graphite CLI using well-known package managers (Homebrew and NPM). These are provided for user information and do not trigger any automatic runtime downloads or executions.
  • [COMMAND_EXECUTION]: Documentation lists various CLI commands such as gt init, gt create, and gt submit. These are represented in Markdown code blocks for instructional purposes only; the skill has no mechanism to execute these commands directly or through a shell runner.
  • [CREDENTIALS_SAFE]: While the skill explains the gt auth command for GitHub integration, it does not include hardcoded secrets, request sensitive environment variables, or provide methods for exfiltrating credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:18 PM