zero-skills
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: A thorough review of the 23 files provided confirms that the skill is legitimate and serves its stated purpose as a developer aid. No obfuscation, persistence mechanisms, or privilege escalation attempts were found.
- [EXTERNAL_DOWNLOADS]: The skill contains scripts like 'setup-demo.sh' and 'verify-tutorial.sh' that download the 'goctl' tool and clone the 'ai-context' repository. These resources originate from the official 'zeromicro' GitHub organization, which is the trusted author of the go-zero framework.
- [COMMAND_EXECUTION]: Advanced skill templates demonstrate the use of Claude Code's dynamic context features, such as executing 'find', 'pwd', and 'grep' to discover project files. These commands are benign discovery operations typical for an AI coding assistant.
- [CREDENTIALS_UNSAFE]: All documentation, pattern guides, and troubleshooting files use generic placeholders (e.g., 'user:password@tcp(localhost:3306)/database') for sensitive configuration values, preventing the accidental exposure of real credentials.
Audit Metadata