folder-sync
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
sync_all_skills.pyscript executes a helper script usingsubprocess.run. The implementation uses a list-based argument structure and avoids invoking a shell (shell=Trueis not used), which is a secure method that prevents shell injection vulnerabilities. - [SAFE]: The core synchronization logic in
sync_folders.pyutilizes standard Python libraries such asshutil,pathlib, andos. Path resolution is handled correctly using.resolve(), and file operations are limited to the user-specified source and target directories. - [SAFE]: No malicious patterns, such as prompt injection, hardcoded credentials, unauthorized network communication, or persistence mechanisms, were detected in any of the skill files.
Audit Metadata