skills/google/capsem/dev-just/Gen Agent Trust Hub

dev-just

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • Development Governance and Surface Control: The skill defines a strict allowlist for public commands in config/public-surface.toml, requiring explicit approval for new recipes. This practice enhances project security by limiting the command surface and preventing accidental exposure of internal scripts.
  • Command Execution Primitives: The skill documents standard development utilities such as just exec and just shell, which are used to run commands in temporary, isolated virtual machines. These are intended for development and testing within the project's specific infrastructure.
  • Local Audit and Testing: The documentation includes instructions for running local security and consistency audits using standard tools like uv and pytest. These commands are used to verify the project's public API surface and maintain build integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:44 PM
Security Audit — agent-trust-hub — dev-just