init-makefiles

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of official CLI tools for Vercel, Railway, Cloudflare, and Supabase using their canonical installation scripts and registries (e.g., railway.com/install.sh). These sources are well-known technology providers.\n- [COMMAND_EXECUTION]: Generated Makefiles include automated routines for development server management and deployment. Port hygiene logic is implemented to ensure that only project-relevant processes (e.g., node, bun, next) are terminated when reclaiming ports.\n- [CREDENTIALS_UNSAFE]: Secret management is handled by instructing the agent to set GitHub Actions secrets via the gh CLI. Documentation explicitly forbids storing tokens on disk or echoing them in logs.\n- [COMMAND_EXECUTION]: Scenario G (MacBook shipping) implements a secure pipeline using rsync over SSH with archive and extended attribute preservation, ensuring bundle integrity during remote deployment.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 10:41 PM
Security Audit — agent-trust-hub — init-makefiles