scaffold-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Bash, Python, and Bun/TypeScript scripts to perform project auditing, configuration merging, and file generation. These operations are essential for its purpose as a scaffolding tool and include built-in validation logic to ensure plan integrity before execution.
- [EXTERNAL_DOWNLOADS]: Verification scripts fetch documentation content from official agent domains (docs.devin.ai) and established documentation repositories (github.com/github/docs). These network operations are limited to retrieving plain-text documentation to verify hook contracts and do not execute remote code.
- [DATA_EXPOSURE]: The skill manages agent-specific configuration files such as
.claude/settings.json,.codex/hooks.json, and~/.claude.json. These interactions are scoped to registering hook handlers and enabling workspace trust for the specific project, following standard practices for local developer utilities.
Audit Metadata