fallow

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates legitimate codebase analysis tasks using the Fallow toolset. It includes defensive instructions for the agent, such as treating configuration files as untrusted input and warning against remote configuration extensions.
  • [SAFE]: Installation instructions leverage standard package managers (NPM, Cargo) and well-known registries. The Node.js bindings are distributed via a scoped package (@fallow-cli/fallow-node), which is a standard practice for reducing namespace conflicts.
  • [SAFE]: Data-sharing features, such as uploading function inventories or source maps to the Fallow cloud service, are clearly documented as part of the tool's runtime monitoring capabilities and require explicit user action or configuration of API keys.
  • [SAFE]: No patterns of obfuscation, prompt injection, unauthorized data access, or malicious persistence were identified in the skill content or its associated references.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 07:47 AM
Security Audit — agent-trust-hub — fallow