machina

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches an installation script from the developer's official GitHub repository (machina-sports/machina-cli).
  • [REMOTE_CODE_EXECUTION]: Provides instructions to download and run a shell script for CLI setup, with an explicit advisory to inspect the script before execution to ensure safety.
  • [DATA_EXFILTRATION]: Facilitates the upload of local project directories to a cloud pod via 'machina template push', a core functionality documented in the skill's risk metadata.
  • [COMMAND_EXECUTION]: Leverages the 'machina-cli' binary for all project management and data access tasks.
  • [CREDENTIALS_UNSAFE]: Instructs users on providing API keys for authentication, recommending the use of the CLI's interactive login or environment variables rather than hardcoding.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 06:25 AM
Security Audit — agent-trust-hub — machina