one-password
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches a GPG signing key from 1Password's official domain (downloads.1password.com) for CLI installation on Linux. This is a standard and expected operation for the tool.
- [COMMAND_EXECUTION]: Demonstrates the execution of the 1Password
opCLI tool through shell commands and Python'ssubprocessmodule. These commands are used to retrieve vault items and manage authentication as part of the skill's primary purpose. - [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill is designed to improve security posture by preventing the hardcoding of secrets.
Audit Metadata