physical

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads location data in CSV format from the GitHub repository laris-co/nat-location-data using the GitHub CLI. This is the intended data source for providing location awareness.
  • [COMMAND_EXECUTION]: The skill executes a local shell script (location-query.sh) that invokes gh and duckdb to process location records. These tools are used for their standard analytical purposes without any signs of misuse.
  • [SAFE]: The implementation is straightforward and matches the stated purpose. No obfuscation, unauthorized data exfiltration, or prompt injection attempts were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 06:41 PM