kg-pack
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones the
agent-kgpacksrepository from GitHub (https://github.com/rysweet/agent-kgpacks.git). This is a repository owned by the skill author, rysweet, used to store the core logic and data for the knowledge packs. - [COMMAND_EXECUTION]: The skill executes various shell commands to manage packs, including
git clone,uv sync,mkdir, andrm. These are standard development operations for setting up and managing a local project environment. - [COMMAND_EXECUTION]: Python scripts within the cloned repository (
scripts/install_pack_skills.py,scripts/build_pack_from_issue.py) are executed usinguv run. These scripts handle the logic for generating skill definitions and building database files locally. - [DATA_EXPOSURE_AND_EXFILTRATION]: The
buildcommand notes that it requires anANTHROPIC_API_KEY. This is used by the local build scripts to interface with the LLM for processing documentation and is not exfiltrated to a third party.
Audit Metadata