dev-setup
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- Remote Script Execution: The skill suggests installing tools like
uvandrustupusing scripts from their official domains. Specifically, it includes a command to installuvviacurl -LsSf https://astral.sh/uv/install.sh | sh. While piped execution is a common practice for these tools, it allows for the execution of remote code. - Agent Autonomy Configuration: The instructions recommend adding broad execution permissions for the AI agent (e.g.,
just *,cargo *) to the agent's local settings. This is intended to streamline the developer experience by reducing repetitive prompts, but it grants the agent significant autonomy within the repository context. - Privilege Escalation: The setup guide includes commands that require elevated privileges on Linux, such as
sudo apt installfor system dependencies like Docker and Bubblewrap. This is a standard requirement for environment provisioning but involve granting root-level access for specific administrative tasks.
Audit Metadata