skills/google/capsem/dev-setup/Gen Agent Trust Hub

dev-setup

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Remote Script Execution: The skill suggests installing tools like uv and rustup using scripts from their official domains. Specifically, it includes a command to install uv via curl -LsSf https://astral.sh/uv/install.sh | sh. While piped execution is a common practice for these tools, it allows for the execution of remote code.
  • Agent Autonomy Configuration: The instructions recommend adding broad execution permissions for the AI agent (e.g., just *, cargo *) to the agent's local settings. This is intended to streamline the developer experience by reducing repetitive prompts, but it grants the agent significant autonomy within the repository context.
  • Privilege Escalation: The setup guide includes commands that require elevated privileges on Linux, such as sudo apt install for system dependencies like Docker and Bubblewrap. This is a standard requirement for environment provisioning but involve granting root-level access for specific administrative tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — dev-setup