extractor
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local CLI tool ('extractor') via subprocess calls in
extract.py. - Evidence:
subprocess.run(command, cwd=str(cwd), env=env, check=False)in the_run_passthroughand_doctorfunctions. - The execution is constrained to a specific local project root or a pre-configured command path (
EXTRACTOR_ROOTorEXTRACTOR_COMMANDenv vars). - User-provided arguments are handled using standard CLI library patterns (Typer) and are passed as a list to
subprocess.run, which effectively mitigates shell injection risks.
Audit Metadata