setup-commit-hooks-and-release
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to inspect the project structure (
cat package.json,ls -la) and create directories (mkdir -p .github/workflows). - [COMMAND_EXECUTION]: Executes package managers (
npm,yarn,pnpm, orbun) to install dependencies. - [COMMAND_EXECUTION]: Uses
chmod +xto modify the execution permissions of generated Husky hook scripts. - [EXTERNAL_DOWNLOADS]: Instructs the agent to download and install several well-known Node.js packages from standard registries (e.g., semantic-release, husky, commitlint).
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local data (
package.json) to determine project configuration without explicit boundary markers or sanitization. This presents an attack surface where malicious content in the project files could attempt to influence the agent's setup process. - Ingestion points:
cat package.jsonin Step 1. - Boundary markers: None identified.
- Capability inventory: Shell execution (
npm install,chmod), directory creation, and file writing across all steps. - Sanitization: None identified.
Audit Metadata