pp-oura

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install tools from GitHub (github.com/mvanhorn/...) and NPM (@mvanhorn/...). These sources correspond to the authorized vendor identity and the downloads are required for the skill's primary functionality.
  • [COMMAND_EXECUTION]: The skill defines and executes specific CLI commands (oura-pp-cli) to interact with the Oura API. These are constrained to health data management and do not include instructions for arbitrary system command execution.
  • [DATA_EXFILTRATION]: A documented feature allows routing output to a webhook URL via the --deliver flag. This is a transparent utility for users to integrate their health data with external services and is not indicative of malicious exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 09:08 AM
Security Audit — agent-trust-hub — pp-oura