new-project-setup

Warn

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads a compiled binary archive from the repository 'rtk-ai/rtk' on GitHub to enable proxy functionality.
  • [COMMAND_EXECUTION]: The downloaded binary is extracted directly into '/usr/local/bin', which is a system-wide executable path requiring elevated permissions in most environments.
  • [COMMAND_EXECUTION]: The skill executes initialization commands ('rtk init') and patches the user's application configuration file located at '~/.claude/settings.json' to inject a tool hook.
  • [EXTERNAL_DOWNLOADS]: The skill fetches project templates and installs additional skills from the vendor repository 'rheinmir/setup'.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 02:19 AM
Security Audit — agent-trust-hub — new-project-setup