skills/bedesj/k-skill/k-skill-setup/Gen Agent Trust Hub

k-skill-setup

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages a local configuration environment by creating the ~/.config/k-skill/ directory and managing a secrets.env file with restricted permissions (0600) to protect sensitive API keys.\n- [EXTERNAL_DOWNLOADS]: It utilizes npx to manage the installation and checking of the skills Node.js package, which is the standard mechanism for this ecosystem.\n- [COMMAND_EXECUTION]: The skill offers optional persistence by configuring crontab (macOS/Linux) or schtasks (Windows) to automate update checks, with instructions explicitly stating this requires prior user consent.\n- [COMMAND_EXECUTION]: It includes a social interaction feature to star a GitHub repository using the gh CLI tool, which is only executed upon explicit user agreement.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 01:00 AM
Security Audit — agent-trust-hub — k-skill-setup