polyglot-git-hooks
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends installing the
lefthookutility through official package registries such as npm, PyPI (via pipx), RubyGems, and Go proxy. - [SAFE]: The skill explicitly advises against dangerous practices such as piping remote scripts directly into a shell (e.g.,
curl | bash), using it as a negative example of what to avoid. - [SAFE]: It provides sound security architecture advice by distinguishing between bypassable local development hooks and mandatory, authoritative CI gates.
- [SAFE]: No evidence of prompt injection, credential harvesting, obfuscation, or unauthorized data access was detected in the skill instructions or reference files.
Audit Metadata