setup-pre-commit
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to install dependencies, initialize Husky hooks, and perform git commits. These actions are localized to the project directory and are expected for the skill's stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill triggers scripts defined in the repository's package.json file, such as 'npm run test' and 'npm run typecheck'. 1. Ingestion points: package.json (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: npm/npx subprocess execution for setup and verification (SKILL.md). 4. Sanitization: Absent. While this creates an indirect injection surface from the project files, it is a standard operation for development automation tools.
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs 'husky', 'lint-staged', and 'prettier' from the official npm registry. These are widely used, well-known developer tools.
Audit Metadata