sesame-onboard

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill downloads and executes an installation script from https://getsesame.dev/install.sh. This domain belongs to the skill's authoring vendor 'getsesame'.
  • [EXTERNAL_DOWNLOADS]: The skill downloads AWS CLI installation packages from awscli.amazonaws.com, which is a well-known and trusted service provider.
  • [COMMAND_EXECUTION]: The skill uses sudo to install the AWS CLI on macOS and Linux. This privilege escalation is limited to the installation of official software from a trusted source.
  • [COMMAND_EXECUTION]: The skill executes aws and sesame CLI commands to verify identity and manage infrastructure deployment as part of its primary function.
  • [CREDENTIALS_SAFE]: The skill features a strong security design that prevents the agent from requesting or viewing the Google Client Secret, instead guiding the user to provide it only within their own terminal session to avoid exposure in chat history.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 09:23 PM
Security Audit — agent-trust-hub — sesame-onboard