skills/rysweet/agent-kgpacks/kg-pack/Gen Agent Trust Hub

kg-pack

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill clones the agent-kgpacks repository from GitHub (https://github.com/rysweet/agent-kgpacks.git). This is a repository owned by the skill author, rysweet, used to store the core logic and data for the knowledge packs.
  • [COMMAND_EXECUTION]: The skill executes various shell commands to manage packs, including git clone, uv sync, mkdir, and rm. These are standard development operations for setting up and managing a local project environment.
  • [COMMAND_EXECUTION]: Python scripts within the cloned repository (scripts/install_pack_skills.py, scripts/build_pack_from_issue.py) are executed using uv run. These scripts handle the logic for generating skill definitions and building database files locally.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The build command notes that it requires an ANTHROPIC_API_KEY. This is used by the local build scripts to interface with the LLM for processing documentation and is not exfiltrated to a third party.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 04:31 PM
Security Audit — agent-trust-hub — kg-pack