NYC

oh-my-ag-mcp-integration

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • EXTERNAL_DOWNLOADS (MEDIUM): The command bunx oh-my-ag downloads and executes a package at runtime. The package is maintained by an unknown source (user 'first-fluke' on GitHub), which does not belong to the list of trusted organizations. This allows for the execution of unverified third-party code.
  • COMMAND_EXECUTION (LOW): The skill instructs the agent or user to execute several CLI commands including installation of prerequisites (bun, uv) and diagnostic tools (oh-my-ag doctor). while these are functional, they involve running external binaries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 06:40 PM