linter-setup

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill employs a research-driven protocol for selecting quality tools. It uses generic search templates to identify community-standard tools for the detected tech stack and presents these options to the user, avoiding hardcoded or untrusted third-party scripts.
  • [SAFE]: Configuration and installation steps utilize well-known package managers (e.g., npm, pip, cargo) and standard infrastructure frameworks (e.g., Husky, pre-commit). The skill mandates a 'Strict-by-default' approach and requires user approval to loosen any rules.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data such as plan.md and architecture reports, and performs web searches to identify relevant tools. This creates an attack surface where malicious project documentation or search results could attempt to influence the agent's behavior. Ingestion points: Project files (plan.md, architecture reports) and WebSearch results. Boundary markers: The skill uses a research-and-selection model where results are presented as options for user approval. Capability inventory: The skill can write configuration files, execute package manager installation commands, and modify Git hooks. Sanitization: The skill relies on generic search queries and mandatory user review of tool options before acting.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 03:12 PM
Security Audit — agent-trust-hub — linter-setup