setup-skillferry

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill describes a legitimate workflow for managing agent configurations using the skillferry utility. It explicitly documents security best practices, such as using secret references rather than raw values (e.g., secret:env/NAME) and utilizing a [protect] mechanism to prevent machine-local state or credentials from being included in shared workspaces.
  • [COMMAND_EXECUTION]: The workflow instructions involve standard CLI operations for the tool's intended purpose, such as skillferry plan, skillferry apply, and skillferry doctor. These commands are used to manage file synchronization and verify configuration health.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing workspace definitions from local files or Git repositories.
  • Ingestion points: Git repository clones and workspace initialization in SKILL.md.
  • Boundary markers: The skillferry plan step provides a human-review checkpoint to inspect changes and portability grades before they are applied.
  • Capability inventory: File writing and configuration management across agent platforms (Codex, Claude Code, DeepSeek Harness).
  • Sanitization: The skill emphasizes secret management through references and the use of per-path hash ledgers to track and verify changes, reducing the risk of accidental or malicious configuration injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 04:34 AM
Security Audit — agent-trust-hub — setup-skillferry