repo-oracle
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- Dynamic Python Execution: The skill utilizes
uv runto execute Python code blocks for auditing repository consistency. These snippets perform logic such as parsing YAML/JSON, validating schemas, and checking file existence. While intended for repository maintenance, the execution of dynamic scripts is a pattern that warrants review to ensure only intended logic is processed. - Repository Metadata Access: The skill interacts with the repository's configuration files, including
.github/CODEOWNERSandmanifest.yaml, which contain identity-related information about reviewers and repository ownership. - External Tooling and Network Interaction: The skill utilizes the GitHub CLI (
gh) to query repository settings and labels. This involves network requests to the GitHub API to fetch real-time repository metadata. These operations are restricted to read-only queries. - Command Injection Protections: The instructions explicitly forbid the direct inclusion of user-provided strings in shell commands. It mandates the use of pre-validated placeholders to prevent potential command injection vulnerabilities.
- Package Management: The skill specifies dependencies like
pyyamlfor its auditing scripts. These are fetched via standard package management tools from established registries.
Audit Metadata