pcr-setup
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate file system modifications required for its stated purpose, such as creating the
.agents/docs/directory and updating documentation files like AGENTS.md. - [SAFE]: It uses explicit markers (PCR:START and PCR:END) to delimit its configuration block, ensuring it does not interfere with project-specific instructions or other tools' regions.
- [SAFE]: External URLs target the developer's official repository (hyfdev) and a public project from a well-known organization (google-labs-code), which is consistent with the skill's functionality and documentation needs.
- [SAFE]: The instructions emphasize human review and manual verification (the vouch system) for all AI-generated documentation, which is a security best practice for managing AI-accumulated context.
- [SAFE]: The npx commands mentioned in the instructions (e.g., for updating the skill or linting design docs) are standard developer tools and are presented as suggestions or maintenance procedures rather than hidden execution patterns.
Audit Metadata