ai-coding-agents-release-distribution
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides documentation and templates for the 'curl | bash' remote script execution pattern, which is a common distribution method for developer tools.
- Evidence:
assets/templates/install-script-skeleton.shcontains a usage example:curl -fsSL https://get.yourorg.example/install.sh | bash. - Evidence:
SKILL.mdidentifies 'OSS install scripts (*.sh + *.ps1)' as a strong implementation pattern for distribution. - Context: These patterns are provided as skeletons for developers to adapt for their own software distribution and are presented within the context of release engineering design. The templates themselves include security checks like platform detection and SHA-256 checksum verification.
- [EXTERNAL_DOWNLOADS]: The skill references official installation commands and packages for established AI products from well-known services and trusted organizations.
- Evidence:
references/openai-codex-install-update-and-doctor.mdreferences the official install script for OpenAI Codex:curl -fsSL https://chatgpt.com/codex/install.sh | sh. - Evidence:
references/openai-codex-install-update-and-doctor.mdreferences official package registry installations:npm install -g @openai/codexandbrew install --cask codex. - Context: These references target OpenAI, an established and trusted technology organization, as part of a case study on real-world coding-agent distribution models.
Audit Metadata