skills/steipete/agent-scripts/oracle/Gen Agent Trust Hub

oracle

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and execute the @steipete/oracle package from the npm registry using npx.
  • [COMMAND_EXECUTION]: The functionality is accessed through various shell commands for bundling files, performing dry runs, and managing sessions.
  • [DATA_EXFILTRATION]: By design, the tool aggregates local file content (source code, documentation) to be processed by external AI services via API or browser automation. The skill documentation includes specific safety sections advising users to exclude secrets like .env files and auth tokens from these uploads.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 02:32 PM
Security Audit — agent-trust-hub — oracle