nihaisha

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is designed for educational purposes, organizing high-density TCM course material into searchable references with explicit safety boundaries and medical disclaimers.
  • [COMMAND_EXECUTION]: The skill provides search utilities like scripts/search_screenshots.py and scripts/search_pdf_evidence.py intended for use by the AI agent to retrieve specific course excerpts.
  • [COMMAND_EXECUTION]: Developer-oriented evaluation scripts in evals/scripts/ use subprocess.Popen and subprocess.run to execute codex commands for automated quality benchmarks. These are separate from the agent's primary task.
  • [EXTERNAL_DOWNLOADS]: The nihaisha_kg module includes an asset manager that downloads RAG indices and SQLite databases from Hugging Face. The downloads target a repository owned by the author (JuneYao) and follow standard practices for supplemental data management.
  • [SAFE]: A shell script install_as_skill.sh is provided for the user to locally install the skill into their agent's directory. It performs standard file system operations like mkdir and rsync without requesting elevated privileges.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 03:27 PM
Security Audit — agent-trust-hub — nihaisha