streamdeck-lab

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's setup script (run.sh) checks for the presence of the 'uv' package manager and executes its official installation script from astral.sh (a well-known Python developer tooling service) if it is missing. This is considered safe as it utilizes a trusted, well-known source for developer tooling.
  • [COMMAND_EXECUTION]: The backend communication bridge in bridge.py uses subprocess.run to call local CLI commands and Python data-processing scripts. These calls use list-based arguments rather than shell strings, which effectively mitigates command injection risks.
  • [SAFE]: File system interactions are limited to reading templates and writing evaluation results within the skill's own directory structure and the designated user workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — streamdeck-lab