setup-shadowfax

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user to execute Node.js scripts (init.js and install-cursor.js) to perform initialization tasks. This is standard behavior for setup-oriented skills.
  • [SAFE]: The logic in scripts/init.js is limited to searching for a plugin root directory and creating local files within the current working directory's .shadowfax folder. It uses standard Node.js fs and path modules for legitimate file operations and contains no obfuscation, credential harvesting, or unauthorized remote execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 10:33 AM
Security Audit — agent-trust-hub — setup-shadowfax