klh-settings-audit
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard, read-only system commands such as
ls,find, andcatto detect project structure and configuration files. These operations are limited to metadata collection for project analysis. - [REMOTE_CODE_EXECUTION]: The skill mentions external tools like
@linear/mcp-serverandnpx, but only as recommendations for the user to add to their own local environment configuration (.mcp.json). It does not automatically execute remote code. - [DATA_EXPOSURE]: The skill checks for existing configuration files (
.claude/settings.json,.mcp.json) to provide merge instructions. It does not attempt to exfiltrate this data or access sensitive user credentials outside of standard project configuration. - [EXTERNAL_DOWNLOADS]: The skill references documentation and registry domains from well-known and trusted providers (e.g., GitHub, Sentry, Vercel, Docker, Python, Rust) as suggested allow-list entries for the user's web fetch permissions.
Audit Metadata