skills/leonardoacosta/skills/fallow/Gen Agent Trust Hub

fallow

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with the official vendor domains fallow.tools and fallow.cloud for documentation, licensing, and runtime coverage features. These interactions are legitimate and essential for the tool's stated functionality.
  • [SAFE]: Remote code execution is performed through standard package managers using pnpm dlx or npx to run the fallow binary. The instructions correctly advise users to prefer version-pinned local installs for monorepo consistency and security.
  • [SAFE]: Persistence and automation are achieved via pre-commit git hooks and agent-specific hooks (modifying .claude/settings.json). These mechanisms are documented features designed to enforce codebase health gates during development.
  • [SAFE]: The skill follows secure practices for sensitive data by using environment variables (e.g., FALLOW_API_KEY) for authentication with its cloud service, rather than hardcoding credentials.
  • [SAFE]: The tool employs standard static analysis techniques (using the Oxc parser) and explicitly documents its inability to resolve fully dynamic imports, reflecting a transparent and well-defined security model.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — fallow