check-upstream-flake
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill queries the public Chromium LUCI Analysis REST API at
analysis.api.luci.appto retrieve test history statistics. This is an expected operation for a tool designed to check upstream flakiness. - [COMMAND_EXECUTION]: Documentation describes executing a local Python script (
./script/check-upstream-flake.py) with user-provided test names as arguments. This is a standard CLI interaction pattern. - [DATA_EXFILTRATION]: While the skill makes network requests, it does so to fetch data from a well-known service (Chromium's LUCI). It does not access sensitive local files (like
.sshor.aws) or attempt to transmit private user data to unknown third parties. - [INDIRECT_PROMPT_INJECTION]: The skill processes test names and API responses. While these could technically contain malicious instructions, the skill is documented with
disable-model-invocation: true, which prevents the LLM from processing the output as instructions, thereby mitigating this attack surface.
Audit Metadata