setup-commit-hooks-and-release

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to inspect the project structure (cat package.json, ls -la) and create directories (mkdir -p .github/workflows).
  • [COMMAND_EXECUTION]: Executes package managers (npm, yarn, pnpm, or bun) to install dependencies.
  • [COMMAND_EXECUTION]: Uses chmod +x to modify the execution permissions of generated Husky hook scripts.
  • [EXTERNAL_DOWNLOADS]: Instructs the agent to download and install several well-known Node.js packages from standard registries (e.g., semantic-release, husky, commitlint).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local data (package.json) to determine project configuration without explicit boundary markers or sanitization. This presents an attack surface where malicious content in the project files could attempt to influence the agent's setup process.
  • Ingestion points: cat package.json in Step 1.
  • Boundary markers: None identified.
  • Capability inventory: Shell execution (npm install, chmod), directory creation, and file writing across all steps.
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — setup-commit-hooks-and-release