trixel-hermes
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/git_sync.shperforms automated Git synchronization using a blindgit add .followed bygit push. This behavior poses a risk of accidentally exfiltrating sensitive local data, environment files, or credentials to remote repositories without manual review of the staged changes. - [COMMAND_EXECUTION]: The skill integrates with
termux-sms-sendfor automated messaging and utilizestermux-battery-statuswithinscripts/device_health.shto monitor system state. - [EXTERNAL_DOWNLOADS]: The
scripts/git_sync.shutility performsgit pulloperations, which retrieve and integrate code updates from remote Git sources into the local environment. - [COMMAND_EXECUTION]: The
scripts/file_organizer.pyscript performs mass file movement operations across standard Android storage paths (such as/Download,/Documents, and/Pictures) based on file extensions.
Audit Metadata