setup-project

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches normative rules and best practices from the The-Focus-AI/standards repository on GitHub.
  • [REMOTE_CODE_EXECUTION]: Installs agent skills from remote repositories using the skills CLI tool, typically following a locked set of definitions.
  • [COMMAND_EXECUTION]: Executes shell commands via mise, pnpm, and git to configure the project environment, initialize repositories, and manage dependencies.
  • [DATA_EXFILTRATION]: Uses fnox and 1Password for secret management, specifically instructing the agent to never hardcode credentials and instead use vault item mappings.
  • [PROMPT_INJECTION]: Ingests external instructions from the The-Focus-AI/standards repository (Ingestion points) which are processed to guide project setup; it lacks explicit delimiters or sanitization for these external files (Boundary markers, Sanitization), while possessing shell and file system capabilities (Capability inventory).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 08:08 AM
Security Audit — agent-trust-hub — setup-project