setup-and
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate repository configuration tasks such as creating or moving markdown files (AGENTS.md, CLAUDE.md) and managing GitHub labels. These actions are within the expected scope of a setup utility.
- [EXTERNAL_DOWNLOADS]: The skill mentions using
npxto install additional skills from known repositories (Andiedie/skills,mattpocock/skills). As the skill is authored by 'andiedie', the reference to their own repository is a standard vendor resource operation and does not escalate the risk level. - [COMMAND_EXECUTION]: The skill includes documentation for
npx --yes skills addcommands. These are presented as guidance for the user to install missing environment components and are not executed silently or without user context. - [DATA_EXFILTRATION]: No patterns of sensitive data access or external transmission to unauthorized domains were found. Operations are restricted to the local repository and the connected GitHub workflow authority.
Audit Metadata