skills/google/adk-recipes/repo-oracle/Gen Agent Trust Hub

repo-oracle

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Dynamic Python Execution: The skill utilizes uv run to execute Python code blocks for auditing repository consistency. These snippets perform logic such as parsing YAML/JSON, validating schemas, and checking file existence. While intended for repository maintenance, the execution of dynamic scripts is a pattern that warrants review to ensure only intended logic is processed.
  • Repository Metadata Access: The skill interacts with the repository's configuration files, including .github/CODEOWNERS and manifest.yaml, which contain identity-related information about reviewers and repository ownership.
  • External Tooling and Network Interaction: The skill utilizes the GitHub CLI (gh) to query repository settings and labels. This involves network requests to the GitHub API to fetch real-time repository metadata. These operations are restricted to read-only queries.
  • Command Injection Protections: The instructions explicitly forbid the direct inclusion of user-provided strings in shell commands. It mandates the use of pre-validated placeholders to prevent potential command injection vulnerabilities.
  • Package Management: The skill specifies dependencies like pyyaml for its auditing scripts. These are fetched via standard package management tools from established registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:53 AM
Security Audit — agent-trust-hub — repo-oracle