software-devtools
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides detailed and secure guidance for building developer experience (DX) tooling without any malicious instructions.
- [SAFE]: It promotes defensive security practices, specifically advising on supply-chain hardening to mitigate risks such as secret harvesting in CI/CD environments.
- [SAFE]: It recommends secure credential management patterns, such as using platform-native secret storage (e.g., VS Code SecretStorage) rather than plaintext configuration files.
- [SAFE]: All external references are to official documentation for well-known developer frameworks (e.g., Cobra, Typer, LSP) and established package registries (e.g., npm, PyPI, crates.io, NuGet).
Audit Metadata