skills/huangrx6/specforge/sf-onboard/Gen Agent Trust Hub

sf-onboard

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the project's core framework and starter templates from the author's GitHub repository (github:huangrx6/SpecForge). This is a documented part of the initialization process.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx to execute the SpecForge CLI directly from the GitHub repository for environment initialization and runtime upgrades. It also references the skills CLI for installing agent-specific skills from the same source.
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts such as doctor.mjs for environment diagnostics and codebase-index.mjs for cataloging repository metadata. These scripts are part of the framework's internal utility suite.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 08:20 AM
Security Audit — agent-trust-hub — sf-onboard