agent-configuration

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains references to dangerous system commands (e.g., rm -rf /, chmod 777) exclusively within documentation sections. These are used as examples of patterns to be blocked or warned against via security hooks, rather than instructions for the agent to execute them.
  • [EXTERNAL_DOWNLOADS]: The skill recommends using cc-safe via npx for auditing project security. This is presented as a legitimate security best practice for scanning codebases for vulnerabilities.
  • [PROMPT_INJECTION]: The instructions explicitly reinforce agent safety guidelines by forbidding the bypass of authentication checks, the exposure of API keys, or the commitment of secret files like .env to version control.
  • [DATA_EXFILTRATION]: There is no evidence of data exfiltration; the configuration examples for hooks and team settings are focused on local environment management and security monitoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 08:07 AM
Security Audit — agent-trust-hub — agent-configuration