github-search
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill performs GitHub API operations and integrates with other local scripts (treesitter and taxonomy) by executing commands through the
ghCLI andbash. These calls are implemented usingsubprocess.runwith argument lists, which is the recommended secure method to prevent command and shell injection vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: Therun.shscript manages its own Python environment and may download thetyperandrichlibraries from the Python Package Index (PyPI). These are well-known, legitimate libraries used for CLI development and output formatting. The use of these external resources follows established standards for AI agent skills.\n- [SAFE]: The skill processes untrusted data from GitHub (e.g., README files and source code) as part of its primary research purpose. This ingestion is handled through safe API parsing (Base64 decoding and JSON loading) and does not exhibit patterns of malicious instruction following or data exfiltration. The skill also enforces limits on file size and search result counts to ensure predictable behavior and resource usage.
Audit Metadata