create-walkthrough

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes subprocess.run to invoke system utilities including ripgrep (rg), find, git, and python. These tools are used to verify the existence of code structures, file paths, and environment variable defaults. The commands are implemented using list-based arguments with inputs strictly validated against regular expressions to prevent shell injection.
  • [DATA_EXFILTRATION]: The skill accesses local project files and environment variable definitions to verify the accuracy of documentation. The resulting audit data is stored in a local ArangoDB instance via a Unix Domain Socket (/run/user/1000/embry/memory.sock) for session memory, representing local data persistence rather than external exfiltration.
  • [DYNAMIC_EXECUTION]: The memory_integration.py component dynamically loads a taxonomy module from a path relative to the skill's installation directory using importlib.util. Additionally, walkthrough.py uses __import__ to fetch the datetime module, which is a standard Python practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — create-walkthrough