cf-init

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate scaffolding functionality for 1C:Enterprise development. Technical analysis of the Python and PowerShell scripts confirms they are limited to creating directory structures and writing XML metadata files locally.- [SAFE]: The scripts implement defensive coding by using XML entity escaping for user-controlled inputs (Name, Synonym, Vendor), which prevents potential XML injection attacks within the generated scaffold files.- [SAFE]: No network activity, data exfiltration, or credential harvesting patterns were detected. The scripts do not access sensitive system files or environment variables.- [SAFE]: Homoglyph characters detected in XML namespace URLs (specifically the use of Cyrillic 'с' in 'v8.1c.ru') are identified as regional typos consistent with the author's background and the 1C:Enterprise domain. Since these strings are used solely as static metadata constants and are not used for network resolution or execution, they present no security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 11:10 AM
Security Audit — agent-trust-hub — cf-init