jfrog-package-safety-and-download

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the JFrog CLI (jf) to perform GraphQL queries, REST API calls, and binary downloads. It also uses standard shell utilities like jq and grep for data processing and error handling. Inputs are wrapped in quotes to mitigate basic command injection risks.
  • [DATA_EXPOSURE]: The skill creates temporary files in the /tmp directory to store request payloads and response logs. These files contain package-related metadata and are managed using process IDs to prevent naming collisions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 12:22 PM
Security Audit — agent-trust-hub — jfrog-package-safety-and-download