pm
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell commands to manage configuration and output. It uses
grepto verify the existence of the 'ouroboros' configuration in~/.claude/mcp.json. It also usescatin conjunction withpbcopyto read a generated markdown file and copy its contents to the system clipboard. - [COMMAND_EXECUTION]: The instructions include references to a command-line interface (
ooo) for setup and updates. These commands are part of the intended functional suite for the skill and are documented for the user to execute manually if needed. - [PROMPT_INJECTION]: While static analysis flagged potential concealment, the instructions actually direct the agent to show internal state alerts (e.g., '[DEV → deferred]') to the user, which is a transparent debugging practice rather than a malicious attempt to hide behavior.
Audit Metadata