soia-env-open-skills-install

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes platform-native CLI tools such as claude and codex to perform plugin management operations. It also runs a local script scripts/inspect_soia_plugins.py to verify the installation status of various domains.
  • [EXTERNAL_DOWNLOADS]: The skill configuration points to official GitHub repositories under the soia-team organization to fetch marketplace data and plugin assets.
  • [REMOTE_CODE_EXECUTION]: Instructions include the execution of a Python installation script fetched from the vendor's own repository to set up experts in the WorkBuddy environment. As the source is the vendor's infrastructure, this is assessed as standard operational behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:47 AM
Security Audit — agent-trust-hub — soia-env-open-skills-install