oracle
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents the use of the '@steipete/oracle' Node.js package. The installation instructions use a standard registry and the package name appears legitimate.
- [SAFE]: Command execution examples (e.g.,
oracle --engine browser,npx -y @steipete/oracle) are standard for the tool's documented purpose of repository bundling and model interaction. - [SAFE]: The skill includes explicit safety advice, warning the user not to attach secrets like
.envfiles or authentication tokens when using the tool. - [SAFE]: Usage of remote browser host parameters (
--remote-host,--remote-token) is documented for legitimate remote execution scenarios and includes a prompt for a secret token which is not hardcoded.
Audit Metadata