holochain

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute environment setup scripts from nixos.org and determinate.systems, and it references cloning the official kangaroo-electron repository from Holochain's GitHub. These sources are well-known and expected within the Holochain ecosystem.
  • [COMMAND_EXECUTION]: Instructs the agent and user to execute various shell commands using the Holochain CLI (hc), Nix, Cargo, and Bun. These operations are necessary for the intended purpose of building, testing, and packaging hApps.
  • [PROMPT_INJECTION]: The skill includes a ReviewZome workflow that directs the agent to analyze external (user) code. While this represents an indirect prompt injection surface (Ingestion points: User zome code; Boundary markers: absent; Capability inventory: hc, cargo, nix subprocess calls; Sanitization: absent), it is an inherent property of its function as a code-review tool and does not contain malicious patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 06:17 AM
Security Audit — agent-trust-hub — holochain