configure-security
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses dynamic context injection (the
!findpattern) to gather information about project structure and existing configurations at load time, which is a legitimate use for environment discovery.- [SAFE]: Network operations viaWebSearchandWebFetchare directed at trusted organizations and well-known services (e.g., GitHub releases, PyPI, and Crates.io) to retrieve tool versioning metadata.- [SAFE]: The skill automates the installation of recognized security tools such asgitleaks,pip-audit, andcargo-auditfrom official sources using standard package managers (go install,uv,cargo).- [SAFE]: The provided templates for GitHub Actions, Dependabot, and security policies adhere to security best practices and do not contain malicious instructions or exfiltration patterns.
Audit Metadata