linter-formatter-init

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/setup.py script executes shell commands via subprocess.run to interact with the environment's package managers.
    • It executes commands for bun, npm, pnpm, or yarn to install development dependencies.
    • It calls husky to initialize git hook management within the target project.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the download of standard Node.js ecosystem packages from the official NPM registry via the local package manager.
    • Targeted packages include industry-standard tools like @biomejs/biome, eslint, prettier, and vitest.
  • [PERSISTENCE]: The skill establishes automated triggers for code execution during the development lifecycle.
    • It adds a prepare script to the project's package.json to ensure hooks are set up on installation.
    • It creates a .husky/pre-commit file and grants it execution permissions (chmod 0o755) to run lint-staged on every commit.
  • [SAFE]: The skill's operations are transparent and confined to the specified project root.
    • Configuration files such as biome.json and .eslintrc.json are created from standard templates defined in the script and asset files.
    • File modifications are restricted to common project configuration files (package.json, .vscode/settings.json) and project-specific tooling directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — linter-formatter-init