skf-setup

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts via uv run and several CLI tools including gh, ccc, qmd, and ast-grep to detect the environment state and manage project configurations. These operations are consistent with the skill's stated purpose of initializing a development environment.\n- [EXTERNAL_DOWNLOADS]: The documentation provides links to official installation pages for trusted development tools, including Astral's uv and GitHub's CLI. No automated remote script execution from untrusted or unknown sources was detected.\n- [DATA_EXFILTRATION]: No evidence of unauthorized data transmission was found. The skill interacts with local configuration files (forge-tier.yaml, preferences.yaml) and utilizes standard CLI tools within the scope of the project directory.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 05:05 PM
Security Audit — agent-trust-hub — skf-setup