finish-setup

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands defined in the project (such as db:migrate) to synchronize database schemas.
  • [DATA_EXFILTRATION]: The skill reads local .env and .env.local files to verify service configurations. It explicitly instructs the agent to report only if keys are set or unset and never to print the actual secret values.
  • [PROMPT_INJECTION]: The skill parses project files like billing plan definitions and environment templates to guide its actions, which constitutes an indirect prompt injection surface if the project files are untrusted.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:16 AM
Security Audit — agent-trust-hub — finish-setup