setup-squidpy-remote-tool

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads a Python wheel from https://connect.aiscientist.tools/downloads/tuplatform_connect-0.3.0-py3-none-any.whl. This is documented as a vendor-specific SDK ('tuplatform-connect') required for relaying tools. The download is pinned with a SHA-256 hash (3fad5eee5ecf7887a693d93ccd1aa112dc0955617a885d1fc3daded0030f9ae0) for integrity verification.
  • [COMMAND_EXECUTION]: The skill instructs the user to execute shell commands to set up virtual environments, install dependencies via pip, and run local Python scripts (setup_skill_preflight.py). These are standard installation and validation steps for technical tools.
  • [SAFE_PRACTICES]: The skill explicitly advises against putting credentials in command arguments or shell history. It promotes the use of tu remote login for device-based authorization and warns against using non-loopback binds without proper API tokens. It also guides users to store provider data and credentials outside of version control.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:19 AM
Security Audit — agent-trust-hub — setup-squidpy-remote-tool