polyglot-git-hooks

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends installing the lefthook utility through official package registries such as npm, PyPI (via pipx), RubyGems, and Go proxy.
  • [SAFE]: The skill explicitly advises against dangerous practices such as piping remote scripts directly into a shell (e.g., curl | bash), using it as a negative example of what to avoid.
  • [SAFE]: It provides sound security architecture advice by distinguishing between bypassable local development hooks and mandatory, authoritative CI gates.
  • [SAFE]: No evidence of prompt injection, credential harvesting, obfuscation, or unauthorized data access was detected in the skill instructions or reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 02:32 PM
Security Audit — agent-trust-hub — polyglot-git-hooks