pick-copilot-tag
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bash script (
check-proposals.sh) that automates version checking. This script uses established system utilities including the GitHub CLI (gh),jq, andpython3to parse data with static regex patterns.\n- [EXTERNAL_DOWNLOADS]: The script retrieves JSON metadata and source file content from the official GitHub repositories of Microsoft and Posit-dev. These network operations are limited to well-known services and are used exclusively for determining version compatibility.
Audit Metadata