linter-formatter-init
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/setup.pyscript executes shell commands viasubprocess.runto interact with the environment's package managers.- It executes commands for
bun,npm,pnpm, oryarnto install development dependencies. - It calls
huskyto initialize git hook management within the target project.
- It executes commands for
- [EXTERNAL_DOWNLOADS]: The skill triggers the download of standard Node.js ecosystem packages from the official NPM registry via the local package manager.
- Targeted packages include industry-standard tools like
@biomejs/biome,eslint,prettier, andvitest.
- Targeted packages include industry-standard tools like
- [PERSISTENCE]: The skill establishes automated triggers for code execution during the development lifecycle.
- It adds a
preparescript to the project'spackage.jsonto ensure hooks are set up on installation. - It creates a
.husky/pre-commitfile and grants it execution permissions (chmod 0o755) to runlint-stagedon every commit.
- It adds a
- [SAFE]: The skill's operations are transparent and confined to the specified project root.
- Configuration files such as
biome.jsonand.eslintrc.jsonare created from standard templates defined in the script and asset files. - File modifications are restricted to common project configuration files (
package.json,.vscode/settings.json) and project-specific tooling directories.
- Configuration files such as
Audit Metadata