bootstrap-prelude

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local repository tools such as formatters, linters, type checkers, and test runners to verify code changes.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the better-result library if the project does not already have an established expected-failure foundation.
  • [DATA_EXFILTRATION]: No exfiltration activity was found. The skill provides a Redacted wrapper in prelude.ts to help developers avoid accidental logging of sensitive data.
  • [PROMPT_INJECTION]: The skill maps repository instructions and source code, creating an indirect prompt injection surface. Ingestion points: Reads repository instructions, manifests, and source files (Step 1). Boundary markers: Absent. Capability inventory: Local script execution and package installation (Steps 3, 5). Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 05:33 PM
Security Audit — agent-trust-hub — bootstrap-prelude