table-lab

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official installation script for the uv package manager at https://astral.sh/uv/install.sh. Astral is a well-known organization in the developer community, and referencing its official domain is a standard procedure for environment setup.
  • [COMMAND_EXECUTION]: Local command execution is used for functional requirements, such as managing virtual environments with uv, interacting with a local memory service via curl, and executing diagnostic tools from related skills within the agent's filesystem.
  • [DATA_EXFILTRATION]: Networking activity is restricted to local service calls on the agent's memory component at localhost:8601. No evidence of data being transmitted to external or unauthorized domains was found.
  • [PROMPT_INJECTION]: The workflow instructions in SKILL.md are purely task-oriented, focusing on extraction tuning and memory management. There are no attempts to override safety filters or extract system instructions.
  • [REMOTE_CODE_EXECUTION]: The skill provides a mechanism to install the reputable uv tool from its official source. This is a common and transparent installation pattern used to support the skill's operational requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — table-lab