setup-project
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is project scaffolding and documentation generation, which is a standard and benign utility task.
- [SAFE]: It employs a policy of minimal privilege by explicitly forbidding command execution, package installation, and automated git operations.
- [SAFE]: Modification of existing project files like CLAUDE.md is gated by explicit user confirmation, preventing accidental or malicious overwrites.
- [SAFE]: The skill reads project metadata (e.g., package.json) only for the purpose of framework detection and does not execute the contents of these files.
Audit Metadata