setup-env
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill is designed to read the
.envfile, which is a sensitive path containing credentials and configuration secrets. However, the instructions explicitly command the agent to never print full secret values and only confirm their existence. This access is essential to the primary purpose of the skill, which is local environment setup. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from untrusted sources, specifically project reference files like
.env.exampleand the codebase's source files. - Ingestion points: Reads
.env.example,.env.sample, and various source code files (Step 1, Step 2, and Step 3). - Boundary markers: None explicitly defined in the instructions to separate data from instructions.
- Capability inventory: The skill has file-read capabilities for local files and file-write capabilities for creating
.env.stubfiles. It does not have network access or subprocess execution capabilities. - Sanitization: The instructions require the agent to use clearly fake placeholder values when generating stubs for secrets, reducing the risk of accidental secret leak through the stub file.
Audit Metadata