check-upstream-flake

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill queries the public Chromium LUCI Analysis REST API at analysis.api.luci.app to retrieve test history statistics. This is an expected operation for a tool designed to check upstream flakiness.
  • [COMMAND_EXECUTION]: Documentation describes executing a local Python script (./script/check-upstream-flake.py) with user-provided test names as arguments. This is a standard CLI interaction pattern.
  • [DATA_EXFILTRATION]: While the skill makes network requests, it does so to fetch data from a well-known service (Chromium's LUCI). It does not access sensitive local files (like .ssh or .aws) or attempt to transmit private user data to unknown third parties.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes test names and API responses. While these could technically contain malicious instructions, the skill is documented with disable-model-invocation: true, which prevents the LLM from processing the output as instructions, thereby mitigating this attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:57 PM
Security Audit — agent-trust-hub — check-upstream-flake