graphite-cli
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, composed of Markdown guides (
SKILL.md,graphite_cli_guide.md,diffstackflow.md). It contains no executable scripts (e.g., .sh, .py, .js) or binaries that could perform automated actions on the user's system. - [EXTERNAL_DOWNLOADS]: The reference material includes standard installation instructions for the Graphite CLI using well-known package managers (Homebrew and NPM). These are provided for user information and do not trigger any automatic runtime downloads or executions.
- [COMMAND_EXECUTION]: Documentation lists various CLI commands such as
gt init,gt create, andgt submit. These are represented in Markdown code blocks for instructional purposes only; the skill has no mechanism to execute these commands directly or through a shell runner. - [CREDENTIALS_SAFE]: While the skill explains the
gt authcommand for GitHub integration, it does not include hardcoded secrets, request sensitive environment variables, or provide methods for exfiltrating credentials.
Audit Metadata