one-password

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a GPG signing key from 1Password's official domain (downloads.1password.com) for CLI installation on Linux. This is a standard and expected operation for the tool.
  • [COMMAND_EXECUTION]: Demonstrates the execution of the 1Password op CLI tool through shell commands and Python's subprocess module. These commands are used to retrieve vault items and manage authentication as part of the skill's primary purpose.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill is designed to improve security posture by preventing the hardcoding of secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 05:23 PM
Security Audit — agent-trust-hub — one-password