init-script-contract

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a contract for project setup scripts, emphasizing idempotent and non-interactive execution.- [SAFE]: The instructions mandate pinning dependencies in lockfiles, which reduces the risk of supply chain attacks during the initialization phase.- [SAFE]: The skill includes explicit warnings against anti-patterns that could compromise sandbox security, such as writing files outside the project directory or using global process termination commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 10:08 AM
Security Audit — agent-trust-hub — init-script-contract