oracle-family-scan

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bun to execute local TypeScript scripts (query.ts, sync.ts, fleet-scan.ts) and shell commands to interact with the GitHub CLI (gh). These commands are used to fetch public repository data and issue comments for project management purposes.
  • [EXTERNAL_DOWNLOADS]: The skill interfaces with GitHub APIs to sync registry data. All target repositories (Soul-Brews-Studio/arra-oracle-v3, laris-co/mother-oracle) belong to the skill author's organization or known partners as defined in the vendor context.
  • [PROMPT_INJECTION]: The skill includes instructions for 'Step 9: welcome', which uses the AI to generate personalized responses to community members. It includes clear guidelines for the AI to follow metaphors and language preferences found in the registry, which is a legitimate use of the agent's generative capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 02:56 AM
Security Audit — agent-trust-hub — oracle-family-scan