ai-coding-agents-release-distribution

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides documentation and templates for the 'curl | bash' remote script execution pattern, which is a common distribution method for developer tools.
  • Evidence: assets/templates/install-script-skeleton.sh contains a usage example: curl -fsSL https://get.yourorg.example/install.sh | bash.
  • Evidence: SKILL.md identifies 'OSS install scripts (*.sh + *.ps1)' as a strong implementation pattern for distribution.
  • Context: These patterns are provided as skeletons for developers to adapt for their own software distribution and are presented within the context of release engineering design. The templates themselves include security checks like platform detection and SHA-256 checksum verification.
  • [EXTERNAL_DOWNLOADS]: The skill references official installation commands and packages for established AI products from well-known services and trusted organizations.
  • Evidence: references/openai-codex-install-update-and-doctor.md references the official install script for OpenAI Codex: curl -fsSL https://chatgpt.com/codex/install.sh | sh.
  • Evidence: references/openai-codex-install-update-and-doctor.md references official package registry installations: npm install -g @openai/codex and brew install --cask codex.
  • Context: These references target OpenAI, an established and trusted technology organization, as part of a case study on real-world coding-agent distribution models.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-coding-agents-release-distribution