agent-folder-init
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses a Python script for scaffolding that incorporates several security best practices, including path validation to ensure files are written within the intended workspace and a dry-run mode to allow users to review changes before they are applied.\n- [SAFE]: Security checks within the script specifically refuse to operate on symbolic links or non-file targets, mitigating risks associated with path traversal or overwriting sensitive system files.\n- [SAFE]: The instructions and documentation templates provided are benign and focused on project organization, daily session tracking, and architecture documentation without any detected malicious patterns or prompt injections.\n- [SAFE]: Mentions of external tools such as
npx @shipshitdev/v0are contextually appropriate for the developer and represent intended project scaffolding functionality.
Audit Metadata