engineering-rapid-prototyper

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local bash script scripts/scaffold.sh designed to automate the creation of project structures. The script utilizes safe shell practices (e.g., set -euo pipefail, printf) and is limited to directory and file creation on the local filesystem without invoking external shells or downloading remote payloads.
  • [CREDENTIALS_UNSAFE]: The documentation in references/full-stack-integration.md includes example configuration for environment variables. These examples use clearly labeled placeholders (e.g., example_user, example_pass) and target the .invalid top-level domain, ensuring no real credentials are leaked. Additionally, the scaffolding script correctly includes .env files in its generated .gitignore to prevent accidental credential commits.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the use of industry-standard libraries and framework CLIs, such as npx create-next-app and npx shadcn@latest. All referenced dependencies are well-known, high-reputation packages within the JavaScript ecosystem (e.g., Next.js, Prisma, Supabase, Clerk).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:46 PM
Security Audit — agent-trust-hub — engineering-rapid-prototyper