role-x
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/role-x.pyscript executes git commands (e.g.,git rev-parse,git diff) to gather context signals such as the current branch and modified files. These operations use hardcoded arguments and are confined to the workspace, presenting no command injection risk. - [DATA_EXFILTRATION]: The skill records local telemetry to
~/.config/broomva/role/events.jsonl. Analysis confirms that no network tools or libraries (likerequests,urllib, orcurl) are used to transmit this data externally. - [PRIVILEGE_ESCALATION]: The 'Persona Federation' feature accesses identity facets stored in the user's home directory. The script implements advanced security measures to prevent exploitation, including
O_NOFOLLOWflag usage,fstatvalidation to ensure file ownership, anddir_fdwalks to mitigate TOCTOU (Time-of-check to time-of-use) and symlink traversal attacks. - [DYNAMIC_EXECUTION]: Configuration and lens files are parsed using
yaml.safe_load(), which is the industry standard for preventing arbitrary code execution during YAML deserialization.
Audit Metadata