skill-system-cli

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The main script sk.py acts as a dispatcher that uses subprocess.run to execute other local tool scripts such as tkt.sh, mem.py, msg.py, and skills.sh. This execution is confined to scripts within the repository and includes timeout protections.
  • [EXTERNAL_DOWNLOADS]: The install domain includes operations to manage skill modules, referencing the author's GitHub repository (arthur0824hao/skills) for updates and synchronization. These are documented vendor-owned resources.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data exfiltration was found. The skill manages local messages in a .sisyphus/inbox directory and interacts with a local PostgreSQL database for agent memory.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 12:54 AM