better-chezmoi

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/probe_chezmoi.py executes the chezmoi binary to verify its version and ensure command compatibility. It utilizes subprocess.run to conduct functional tests within isolated temporary directories, preventing side effects on the user's actual dotfiles during the verification phase.
  • [EXTERNAL_DOWNLOADS]: The scripts/official_docs.py script fetches documentation from https://www.chezmoi.io/. This domain belongs to the official project for the utility the skill is designed to manage, which is a well-known and established service.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external official documentation and local CLI output. It manages the risk of indirect prompt injection by instructing the agent to utilize chezmoi diff and apply --dry-run for manual verification before committing any changes to the target state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — better-chezmoi