se2-dev-plugin

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The preparation logic in Prepare.bat and common_posix.sh fetches the uv installer from astral.sh and the busybox binary from frippery.org. These downloads are intended to provision the local environment with required build and shell utilities.\n- [COMMAND_EXECUTION]: The skill executes various CLI tools including git for cloning plugin source code, dotnet for compiling projects, and uv for script execution. These operations are restricted to the tools specified in the skill's manifest.\n- [SAFE]: No malicious patterns such as obfuscation, credential exfiltration, or persistence mechanisms were detected. The skill follows best practices by providing a detailed security review guide (Review.md) for auditing third-party code downloaded during its operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 07:53 AM
Security Audit — agent-trust-hub — se2-dev-plugin