extractor

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local CLI tool ('extractor') via subprocess calls in extract.py.
  • Evidence: subprocess.run(command, cwd=str(cwd), env=env, check=False) in the _run_passthrough and _doctor functions.
  • The execution is constrained to a specific local project root or a pre-configured command path (EXTRACTOR_ROOT or EXTRACTOR_COMMAND env vars).
  • User-provided arguments are handled using standard CLI library patterns (Typer) and are passed as a list to subprocess.run, which effectively mitigates shell injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — extractor