python-native-build

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard diagnostic and build commands (pkg, pip, python, clang, uname, getprop) required for managing Python environments. These are restricted to the intended purpose of resolving compilation and header errors on Android/Termux.
  • [EXTERNAL_DOWNLOADS]: It references the official Termux main repository and the community tur-repo. The instructions explicitly mandate seeking user confirmation before widening the trust boundary to include community repositories or third-party wheel indexes.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests build logs and environment metadata to diagnose failures. While this represents a data ingestion surface, the subsequent actions (installing missing system headers or using venvs) are standard development procedures with no evidence of unsafe interpolation.
  • [DATA_EXFILTRATION]: The check-toolchain.sh script gathers environment facts such as architecture, Android SDK level, and installed package lists. This information is used strictly for local diagnosis, and the skill contains no network commands that could exfiltrate this data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:05 AM
Security Audit — agent-trust-hub — python-native-build