project-scaffold

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard project initialization functionality. It performs validation on project names using a dedicated Python script (scripts/validate_name.py) which enforces strict character restrictions (lowercase alphanumeric and hyphens), effectively preventing malicious command injection or path traversal through user input. All external libraries used in the templates for Node.js and Python are well-known, established packages from official registries. The skill leverages trusted services and GitHub Actions from recognized organizations like Astral, Vercel, and the official Node.js/Python communities.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 08:26 PM