skills/broomva/skills/role-x/Gen Agent Trust Hub

role-x

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/role-x.py script executes git commands (e.g., git rev-parse, git diff) to gather context signals such as the current branch and modified files. These operations use hardcoded arguments and are confined to the workspace, presenting no command injection risk.
  • [DATA_EXFILTRATION]: The skill records local telemetry to ~/.config/broomva/role/events.jsonl. Analysis confirms that no network tools or libraries (like requests, urllib, or curl) are used to transmit this data externally.
  • [PRIVILEGE_ESCALATION]: The 'Persona Federation' feature accesses identity facets stored in the user's home directory. The script implements advanced security measures to prevent exploitation, including O_NOFOLLOW flag usage, fstat validation to ensure file ownership, and dir_fd walks to mitigate TOCTOU (Time-of-check to time-of-use) and symlink traversal attacks.
  • [DYNAMIC_EXECUTION]: Configuration and lens files are parsed using yaml.safe_load(), which is the industry standard for preventing arbitrary code execution during YAML deserialization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:07 PM
Security Audit — agent-trust-hub — role-x