nixos-best-practices

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily educational and instructional, providing a set of rules and patterns for NixOS administration. It does not contain executable malicious code or dangerous instructions.
  • [EXTERNAL_DOWNLOADS]: All external URL references and flake inputs point to trusted organizations in the Nix ecosystem, such as 'nixos' (github.com/nixos/nixpkgs) and 'nix-community' (github.com/nix-community/home-manager).
  • [COMMAND_EXECUTION]: The skill describes the use of standard NixOS administrative tools such as nixos-rebuild, nix flake, and nix search. While these commands involve system-level changes, they are the standard and expected tools for the tasks described in the skill.
  • [DATA_EXFILTRATION]: There are no signs of credential harvesting or data exfiltration. The skill actually promotes security best practices by suggesting the use of age-encrypted secrets for configuration management.
  • [PROMPT_INJECTION]: The instructional language used (e.g., 'CRITICAL: Read Before Making Changes') is standard for documentation and does not attempt to bypass agent safety filters or override core behavioral guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:06 AM
Security Audit — agent-trust-hub — nixos-best-practices