oracle-family-scan
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bunto execute local TypeScript scripts (query.ts,sync.ts,fleet-scan.ts) and shell commands to interact with the GitHub CLI (gh). These commands are used to fetch public repository data and issue comments for project management purposes. - [EXTERNAL_DOWNLOADS]: The skill interfaces with GitHub APIs to sync registry data. All target repositories (
Soul-Brews-Studio/arra-oracle-v3,laris-co/mother-oracle) belong to the skill author's organization or known partners as defined in the vendor context. - [PROMPT_INJECTION]: The skill includes instructions for 'Step 9: welcome', which uses the AI to generate personalized responses to community members. It includes clear guidelines for the AI to follow metaphors and language preferences found in the registry, which is a legitimate use of the agent's generative capabilities.
Audit Metadata