ai-setup-skills

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard command-line tools such as git for repository inspection, and gh or glab for interacting with GitHub and GitLab APIs. These operations are limited to project metadata and issue tracking.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository configuration files and git metadata to suggest setup options. It incorporates a mandatory human-in-the-loop confirmation step, requiring the user to approve all generated text before any files are modified or external tracker resources are created.
  • [DATA_EXPOSURE]: The skill reads .git/config and remote information to determine the correct issue tracker adapter. This usage is restricted to local configuration discovery and does not involve the exfiltration of sensitive credentials or private data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:58 PM
Security Audit — agent-trust-hub — ai-setup-skills