oracle

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the oracle binary and npx commands to bundle codebases and interact with language models.
  • [EXTERNAL_DOWNLOADS]: References the installation and execution of the @steipete/oracle package from the NPM registry.
  • [DATA_EXFILTRATION]: The tool's primary purpose is to collect local file content and transmit it to external LLM providers (via API or browser automation). The documentation includes a dedicated 'Safety' section advising users to redact secrets and exclude sensitive files like .env or private keys before transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — oracle