node-dev
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill recommends several development scripts and tools that execute system commands for project management.
- Evidence: The configuration in SKILL.md uses pnpm and npx for dependency management and git hooks.
- Evidence: The alias.ts script template in references/monorepo.md uses Node.js fs modules to read and write to tsconfig.alias.json for managing path aliases.
- [EXTERNAL_DOWNLOADS]: The skill references external resources for CI/CD automation and configuration.
- Evidence: references/setting-up.md recommends using GitHub Actions workflows from the sxzz/workflows repository.
- [SAFE]: The skill integrates several security-enhancing practices.
- Evidence: The .gitignore template in references/setting-up.md correctly excludes sensitive files like environment variables (.env) and private keys (*.pem).
- Evidence: The suggested pre-commit hook in SKILL.md includes the --ignore-scripts flag when running pnpm install, preventing the execution of potentially malicious scripts during the installation phase.
Audit Metadata