skills/firecrawl/openclaw/oracle/Gen Agent Trust Hub

oracle

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the use of the '@steipete/oracle' Node.js package. The installation instructions use a standard registry and the package name appears legitimate.
  • [SAFE]: Command execution examples (e.g., oracle --engine browser, npx -y @steipete/oracle) are standard for the tool's documented purpose of repository bundling and model interaction.
  • [SAFE]: The skill includes explicit safety advice, warning the user not to attach secrets like .env files or authentication tokens when using the tool.
  • [SAFE]: Usage of remote browser host parameters (--remote-host, --remote-token) is documented for legitimate remote execution scenarios and includes a prompt for a secret token which is not hardcoded.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:53 PM
Security Audit — agent-trust-hub — oracle