conductor-setup

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard development commands such as git init to initialize repositories, git ls-files to audit existing projects, and git status to verify repository hygiene. It also runs a local Python helper script (scripts/resume.py) used to detect and resume partial project setups.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of additional agent capabilities by downloading SKILL.md instruction files from external sources. These sources include official Google Firebase repositories and the vendor's own DevOps repository (gemini-cli-extensions). The process includes a security mechanism to warn users before installing third-party community skills.\n- [COMMAND_EXECUTION]: Performs an automated audit of the current working directory to detect project maturity and extract architecture information from standard manifests like package.json and go.mod. This read-only scan is limited to the project context and respects existing .gitignore and .geminiignore rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:13 PM
Security Audit — agent-trust-hub — conductor-setup