zero-skills

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: A thorough review of the 23 files provided confirms that the skill is legitimate and serves its stated purpose as a developer aid. No obfuscation, persistence mechanisms, or privilege escalation attempts were found.
  • [EXTERNAL_DOWNLOADS]: The skill contains scripts like 'setup-demo.sh' and 'verify-tutorial.sh' that download the 'goctl' tool and clone the 'ai-context' repository. These resources originate from the official 'zeromicro' GitHub organization, which is the trusted author of the go-zero framework.
  • [COMMAND_EXECUTION]: Advanced skill templates demonstrate the use of Claude Code's dynamic context features, such as executing 'find', 'pwd', and 'grep' to discover project files. These commands are benign discovery operations typical for an AI coding assistant.
  • [CREDENTIALS_UNSAFE]: All documentation, pattern guides, and troubleshooting files use generic placeholders (e.g., 'user:password@tcp(localhost:3306)/database') for sensitive configuration values, preventing the accidental exposure of real credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 02:12 AM
Security Audit — agent-trust-hub — zero-skills