replicas-agent

Pass

Audited by Gen Agent Trust Hub on Jun 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for utilizing various CLI tools such as 'gh' (GitHub), 'replicas' (platform CLI), and 'docker' to manage the workspace and perform repository operations. It also details the use of background processes via 'setsid' for previewing services.
  • [DATA_EXFILTRATION]: Outlines procedures for uploading workspace artifacts, including screenshots and recordings, to official platform endpoints and well-known external services like Slack, Linear, Google Drive, and Imgur for the purpose of collaboration and reporting.
  • [CREDENTIALS_UNSAFE]: Guides the agent on the use of sensitive environment variables, such as 'REPLICAS_ENGINE_SECRET', 'LINEAR_ACCESS_TOKEN', and 'SLACK_BOT_TOKEN', to authenticate API requests with the workspace gateway and third-party integrations.
  • [EXTERNAL_DOWNLOADS]: Interacts with official APIs of well-known services (GitHub, Slack, Linear, Google) to synchronize data and manage resources within the developer workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 6, 2026, 04:36 AM
Security Audit — agent-trust-hub — replicas-agent