sync-rules
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute a bundled Node.js script (
scripts/sync-rules.mjs). This script is responsible for calculating file hashes, detecting local modifications (drift), and copying markdown files from the skill's directory to the project's.claude/rules/directory. - [SAFE]: Analysis of the Node.js script confirms it only performs local file system operations (read/write/mkdir) within the project's scope. It does not perform any network requests or use dynamic code execution (like
evalorexec) on untrusted data. - [SAFE]: The skill implements a secure workflow by using the
AskUserQuestiontool to present an approval checklist to the user. This ensures that no files are added or updated without explicit human consent. - [SAFE]: Information gathering is limited to reading
package.jsonandCLAUDE.mdfor technical stack detection, which is consistent with the skill's stated purpose of judging rule relevance.
Audit Metadata