Gardening Skills Wiki

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements its functionality through a series of bash scripts (garden.sh, check-links.sh, check-naming.sh, check-index-coverage.sh, and analyze-search-gaps.sh). These scripts are designed to be executed locally to perform file system operations such as linting markdown files and checking directory structures.
  • [SAFE]: The scripts operate exclusively on local files within the agent's skills directory (typically ~/.claude/skills or a user-specified path). No network operations, credential access, or persistence mechanisms were found.
  • [SAFE]: The analyze-search-gaps.sh script reads from a local search log file (.search-log.jsonl) to identify missing skills based on previous user queries. While this accesses user interaction history, it is performed entirely locally for the stated purpose of maintenance and does not involve any exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:09 PM
Security Audit — agent-trust-hub — Gardening Skills Wiki