devcontainer-setup
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches official development container features, including Git and Node.js, from the GitHub Container Registry (ghcr.io/devcontainers), which is a well-known and trusted service.
- [COMMAND_EXECUTION]: Uses the 'SetFileExecutable' tool to mark the generated 'setup.sh' script as executable, a standard procedure for development environment initialization scripts.
- [DATA_EXFILTRATION]: The skill optionally mounts the user's local '${localEnv:HOME}/.claude' directory into the container to support Claude Code CLI. While this exposes the user's Claude configuration and session history to the container, it is a documented feature that requires explicit user confirmation during the information-gathering phase.
- [PERSISTENCE]: The generated 'setup.sh' script manages symlinks for Claude configuration components (rules, commands, agents, skills) to maintain a consistent environment across container rebuilds.
Audit Metadata