setup-agentic-scaffolding

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses read-only probes (e.g., java -version, jbang --version, docker version, mcp list) to detect the current environment state.
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install tools via official package managers (SDKMAN, Homebrew, Chocolatey, Scoop) and downloads specific, versioned MCP servers from official registries (Maven Central and npm registry) during agent registration.
  • [REMOTE_CODE_EXECUTION]: While it registers MCP servers that run remote code (JBang and npx), it uses pinned versions from official registries, requires explicit user approval before configuration, and delegates the actual execution to the agent runtime itself rather than executing scripts directly during the setup phase.
  • [CREDENTIALS_UNSAFE]: The skill explicitly forbids handling secrets in plaintext, instructing users to use environment variables (CONTEXT7_API_KEY) and secret managers, and mandates redaction of keys in any output or verification logs.
  • [DATA_EXFILTRATION]: No patterns of sensitive data exfiltration were detected. Network operations are limited to official registry resolutions handled by the agent's MCP architecture.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:34 PM