chezmoi

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The bootstrap and installation recipes fetch and execute scripts from well-known and official project sources, including get.chezmoi.io, raw.githubusercontent.com/Homebrew/install (Homebrew), and sh.rustup.rs (Rustup).
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to invoke the chezmoi CLI, which executes local scripts (prefixed with run_) and enables shell command execution within templates via the output function. These operations are core to the tool's functionality, and the documentation consistently instructs the user to review changes using diff and dry-run modes before applying them.
  • [SAFE]: The instructions promote secure data handling, specifically advising against committing plaintext secrets and recommending the use of professional secret management tools like 1Password, Bitwarden, and age encryption.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 10:54 PM
Security Audit — agent-trust-hub — chezmoi