skills/lackeyjb/claude-keep/keep/Gen Agent Trust Hub

keep

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) via the subprocess module in scripts/github_sync.py to interact with remote repositories. Commands are executed using argument lists rather than shell strings, which is a recommended security practice to prevent shell injection.
  • [EXTERNAL_DOWNLOADS]: The skill fetches issue descriptions, titles, and labels from GitHub to populate local work tracking files in the .claude/ directory. These downloads are directed to the official GitHub API via the gh tool.
  • [DATA_EXFILTRATION]: Local work summaries, technical decisions, and progress updates are posted back to GitHub issues as comments. This data transmission is a documented core feature intended to keep remote project boards synchronized with local development progress.
  • [SAFE]: No obfuscation techniques, hardcoded credentials, or unauthorized persistence mechanisms were detected. All file operations are restricted to the local project environment and the standard .claude/ configuration directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 01:00 PM