oracle
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to transmit prompts and local file contents to an external cloud model (ChatGPT) for reasoning tasks. It incorporates explicit safety instructions directing the agent to redact credentials, secrets, and private keys before transmission.
- [COMMAND_EXECUTION]: The skill utilizes the oracle CLI utility to facilitate browser-based interaction with the external model, allowing the agent to pass local context and retrieve reasoning artifacts.
- [PROMPT_INJECTION]: The skill processes potentially untrusted content from local files and terminal outputs by sending them to an external service. It mitigates the risk of indirect prompt injection by providing a rigorous verification workflow that requires checking all external recommendations against local artifacts.
Audit Metadata