llm-wiki
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The system automates the installation of the
bunanduvtools from their official domains (bun.shandastral.sh), which are well-known technology services. It also utilizes a fallback API atdefuddle.mdto process URLs into markdown when local capture methods are unavailable. - [COMMAND_EXECUTION]: The skill invokes system-level utilities such as LibreOffice (
soffice),pandoc, andpdftoppmusing shell commands. These executions are performed by vendored scripts from a trusted organization (Anthropics) and are necessary for document conversion and data recalculation tasks within the workbench environment. - [REMOTE_CODE_EXECUTION]: Setup and upgrade procedures involve executing installation scripts for
bunanduvvia shell piping. As these sources are reputable, established technology providers, this behavior is part of a standard development workflow and is documented here as a benign detection. - [DATA_EXFILTRATION]: The skill identifies a data ingestion surface by fetching content from user-provided URLs (including social media and messaging platforms). To mitigate the risk of accidental exposure of sensitive user data, the skill enforces a mandatory privacy self-check workflow, ensuring the user confirms the absence of secrets before the content enters the system.
Audit Metadata