better-chezmoi
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/probe_chezmoi.pyexecutes thechezmoibinary to verify its version and ensure command compatibility. It utilizessubprocess.runto conduct functional tests within isolated temporary directories, preventing side effects on the user's actual dotfiles during the verification phase. - [EXTERNAL_DOWNLOADS]: The
scripts/official_docs.pyscript fetches documentation fromhttps://www.chezmoi.io/. This domain belongs to the official project for the utility the skill is designed to manage, which is a well-known and established service. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external official documentation and local CLI output. It manages the risk of indirect prompt injection by instructing the agent to utilize
chezmoi diffandapply --dry-runfor manual verification before committing any changes to the target state.
Audit Metadata