monitor-skill-health

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call external tools such as assess, review-code, memory, scheduler, and ticket. This is the core functionality for an orchestrator skill that monitors other components. The commands are constructed using absolute paths to internal project tools (e.g., SKILLS_ROOT / "assess" / "run.sh") rather than untrusted user input, which mitigates command injection risks.
  • [REMOTE_CODE_EXECUTION]: While the skill invokes a review-code tool that may use external LLM providers (OpenAI/Codex), the code itself does not directly download or execute arbitrary remote scripts. The execution flow is strictly controlled within the local repository environment.
  • [DATA_EXFILTRATION]: The skill generates audit reports and ticket drafts. The /run.sh tickets --apply command can interact with GitHub to create issues, but this requires explicit user activation and is limited to reporting findings back to the user's configured repositories.
  • [PRIVILEGE_ESCALATION]: The skill operates within the user's environment and utilizes uv run for dependency management. No sudo usage or attempts to modify system-level configurations were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — monitor-skill-health