chezmoi-workflows

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The setup instructions in references/setup.md facilitate the installation of chezmoi using the command sh -c "$(curl -fsLS get.chezmoi.io)". This is the official and standard installation method for this well-known open-source utility.
  • [EXTERNAL_DOWNLOADS]: The skill performs downloads from get.chezmoi.io for installation and interacts with GitHub repositories via git and the gh CLI for synchronizing dotfiles.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash tool to manage local configuration files, execute chezmoi commands, and perform Git operations.
  • [SAFE]: The skill incorporates security best practices by configuring chezmoi to fail if secrets are detected (secrets = "error") and providing detailed instructions on using external secret managers like 1Password and environment variables to avoid data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:17 AM
Security Audit — agent-trust-hub — chezmoi-workflows