skf-setup
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts via
uv runand several CLI tools includinggh,ccc,qmd, andast-grepto detect the environment state and manage project configurations. These operations are consistent with the skill's stated purpose of initializing a development environment.\n- [EXTERNAL_DOWNLOADS]: The documentation provides links to official installation pages for trusted development tools, including Astral'suvand GitHub's CLI. No automated remote script execution from untrusted or unknown sources was detected.\n- [DATA_EXFILTRATION]: No evidence of unauthorized data transmission was found. The skill interacts with local configuration files (forge-tier.yaml,preferences.yaml) and utilizes standard CLI tools within the scope of the project directory.
Audit Metadata