monitor-herdr
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runandasyncio.create_subprocess_execto interact with system tools likegit,gh(GitHub CLI),crontab, and theherdrCLI. These are used to resolve repository context, manage scheduled tasks, and control agent panes. - [EXTERNAL_DOWNLOADS]: The skill installs dependencies via
uvas defined inpyproject.tomlanduv.lock. All packages (loguru, pytest, python-dotenv, typer, and their dependencies) are sourced from the official Python Package Index (PyPI). - [REMOTE_CODE_EXECUTION]: Although the skill executes shell commands, it does not download and pipe remote scripts to a shell. The commands are limited to local tooling and specific CLI wrappers for the Herdr platform.
- [DATA_EXFILTRATION]: No evidence was found of sensitive data being sent to external domains. Network operations are limited to standard
ghCLI usage for ticket lookups from GitHub and internal socket communication with the Herdr server at~/.config/herdr/herdr.sock.
Audit Metadata