scaffold-hooks

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes Bash, Python, and Bun/TypeScript scripts to perform project auditing, configuration merging, and file generation. These operations are essential for its purpose as a scaffolding tool and include built-in validation logic to ensure plan integrity before execution.
  • [EXTERNAL_DOWNLOADS]: Verification scripts fetch documentation content from official agent domains (docs.devin.ai) and established documentation repositories (github.com/github/docs). These network operations are limited to retrieving plain-text documentation to verify hook contracts and do not execute remote code.
  • [DATA_EXPOSURE]: The skill manages agent-specific configuration files such as .claude/settings.json, .codex/hooks.json, and ~/.claude.json. These interactions are scoped to registering hook handlers and enabling workspace trust for the specific project, following standard practices for local developer utilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:39 AM
Security Audit — agent-trust-hub — scaffold-hooks