marimo-pair-vscode

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill uses authorized marimo-team APIs for notebook manipulation.
  • [COMMAND_EXECUTION]: The skill uses marimo_executeCode to run Python in the notebook kernel, which is its core intended functionality.
  • [EXTERNAL_DOWNLOADS]: The skill manages Python packages via ctx.packages.add and imports JavaScript libraries from the esm.sh CDN, both of which are standard practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted notebook content. Ingestion points: ctx.cells and scratchpad globals. Boundary markers: None. Capability inventory: marimo_executeCode, ctx.packages.add, ctx.edit_cell. Sanitization: None. This surface is low-risk and expected for a notebook interaction tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 09:59 PM
Security Audit — agent-trust-hub — marimo-pair-vscode