monitor-herdr

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run and asyncio.create_subprocess_exec to interact with system tools like git, gh (GitHub CLI), crontab, and the herdr CLI. These are used to resolve repository context, manage scheduled tasks, and control agent panes.
  • [EXTERNAL_DOWNLOADS]: The skill installs dependencies via uv as defined in pyproject.toml and uv.lock. All packages (loguru, pytest, python-dotenv, typer, and their dependencies) are sourced from the official Python Package Index (PyPI).
  • [REMOTE_CODE_EXECUTION]: Although the skill executes shell commands, it does not download and pipe remote scripts to a shell. The commands are limited to local tooling and specific CLI wrappers for the Herdr platform.
  • [DATA_EXFILTRATION]: No evidence was found of sensitive data being sent to external domains. Network operations are limited to standard gh CLI usage for ticket lookups from GitHub and internal socket communication with the Herdr server at ~/.config/herdr/herdr.sock.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — monitor-herdr