lov-xbti-gallery

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes open to launch a URL in the user's browser and uses the gh (GitHub) CLI to fetch repository contents via the official GitHub API. These are intended behaviors for a gallery-browsing skill.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with api.github.com via the gh CLI to list files in a specific repository (skill-publisher/XBTI). This is a standard use of a well-known service to retrieve public metadata.
  • [DYNAMIC_EXECUTION]: The skill uses a small Python one-liner to parse JSON output from the GitHub API. The logic is static and only processes the structure of the JSON to extract directory names, posing no risk of code injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:33 AM
Security Audit — agent-trust-hub — lov-xbti-gallery