oracle
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples for running the
@steipete/oracleCLI tool usingnpx. These commands are used for codebase analysis, token counting, and browser-based AI interactions. - [EXTERNAL_DOWNLOADS]: Uses
npx -y @steipete/oracle, which downloads the latest version of the package from the npm registry if not already present. This is a standard method for running Node.js CLI tools. - [CREDENTIALS_UNSAFE]: The documentation explicitly warns users not to include secrets like
.envfiles or API keys in the bundled files. It also suggests a secure way to inject API keys using 1Password CLI (op item get) rather than hardcoding them. - [SAFE]: The author of the skill ('steipete') is the same as the vendor of the recommended CLI tool (
@steipete/oracle). The domains and tools mentioned (steipete.com, pnpm, npx) are legitimate developer resources. No malicious patterns, obfuscation, or unauthorized data exfiltration were detected.
Audit Metadata