fallow
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts with the official vendor domains
fallow.toolsandfallow.cloudfor documentation, licensing, and runtime coverage features. These interactions are legitimate and essential for the tool's stated functionality. - [SAFE]: Remote code execution is performed through standard package managers using
pnpm dlxornpxto run thefallowbinary. The instructions correctly advise users to prefer version-pinned local installs for monorepo consistency and security. - [SAFE]: Persistence and automation are achieved via pre-commit git hooks and agent-specific hooks (modifying
.claude/settings.json). These mechanisms are documented features designed to enforce codebase health gates during development. - [SAFE]: The skill follows secure practices for sensitive data by using environment variables (e.g.,
FALLOW_API_KEY) for authentication with its cloud service, rather than hardcoding credentials. - [SAFE]: The tool employs standard static analysis techniques (using the Oxc parser) and explicitly documents its inability to resolve fully dynamic imports, reflecting a transparent and well-defined security model.
Audit Metadata