klh-settings-audit

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard, read-only system commands such as ls, find, and cat to detect project structure and configuration files. These operations are limited to metadata collection for project analysis.
  • [REMOTE_CODE_EXECUTION]: The skill mentions external tools like @linear/mcp-server and npx, but only as recommendations for the user to add to their own local environment configuration (.mcp.json). It does not automatically execute remote code.
  • [DATA_EXPOSURE]: The skill checks for existing configuration files (.claude/settings.json, .mcp.json) to provide merge instructions. It does not attempt to exfiltrate this data or access sensitive user credentials outside of standard project configuration.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and registry domains from well-known and trusted providers (e.g., GitHub, Sentry, Vercel, Docker, Python, Rust) as suggested allow-list entries for the user's web fetch permissions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:40 AM
Security Audit — agent-trust-hub — klh-settings-audit