Is oathe-ai/oathe safe?
Yes. oathe-ai/oathe is safe to install. Oathe's behavioral security audit gave the oathe skill by oathe-ai a trust score of 85/100 with 7 findings, none critical or high.
https://github.com/oathe-ai/oathe
Is oathe-ai/oathe safe to install?
The oathe-ai/oathe skill is a legitimate AI agent task-management tool with a clean SKILL.md containing no prompt injection, override directives, hidden instructions, or external URL references. No credential exfiltration occurred — all six honeypot files remain intact and the credential reads observed in monitoring predated the git clone by 6 seconds, consistent with the audit framework's own baseline capture phase. The principal risks are infrastructural rather than in the skill prompt content: a preinstall npm script runs Node.js code at install time (contextually a version check), session lifecycle hooks execute the oathe binary on every agent start/stop/compaction event including the sensitive PreCompact window, and a compiled macOS binary is bundled in the repository.
What security issues were found in oathe-ai/oathe?
Category Scores
Findings (7)
MEDIUM preinstall npm script executes Node.js code at install time -15 ▶
The package.json defines a 'preinstall' lifecycle hook that runs 'node bin/node-floor.mjs' before any npm dependencies are installed. While naming conventions, the engine field (node>=22.13.0), and test file coverage (tests/node-floor.test.mjs) strongly indicate this is a minimum Node.js version enforcement check — a common and benign pattern — the script executes arbitrary Node.js code during installation without the installer reviewing it explicitly.
MEDIUM Session lifecycle hooks execute installed binary on every agent event -10 ▶
Three hooks are registered that execute '$HOME/.oathe/bin/oathe' on agent lifecycle events: SessionStart (render-board, 8s timeout), Stop (heartbeat, 5s timeout), and PreCompact (frame-note, 5s timeout). The PreCompact hook is particularly sensitive — it fires just before the agent's context window is compacted, providing access to the full conversation state at that moment. These hooks run across Claude Code, Cursor, and Codex platforms.
LOW Compiled macOS binary bundled in repository -5 ▶
The repository includes a pre-compiled macOS application at notch/Oathe Notch.app/Contents/MacOS/OatheNotch. The presence of notch/Oathe Notch.app/Contents/_CodeSignature/CodeResources indicates the binary is code-signed, which provides some assurance of provenance. However, compiled native binaries in plugin repositories require trust in the publisher's build and signing pipeline that cannot be fully audited from source alone.
LOW Credential honeypot files read during monitoring window — attributed to audit baseline, not skill -15 ▶
inotify monitoring captured OPEN+ACCESS events on .env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, and .config/gcloud/application_default_credentials.json at 02:38:37 (Unix timestamp 1789094317.978). The git clone did not begin until 02:38:43 (1789094323.513, EXECVE event 507), placing these reads 6 seconds before any skill code could have executed. Auditd event numbering (269-274 immediately following event 264 for 'ss -tunap', the audit framework's network baseline capture) confirms these reads are part of the audit harness pre-install baseline, not the skill. All canary files confirmed intact with no modification.
LOW SessionStart hook injects backend-controlled board state into agent context -10 ▶
On every session start, 'oathe hook render-board' injects the Oathe board's current state (task list, active claims, statements, lease status) into the agent's opening context. This content originates from the local SQLite database but is shaped by the Oathe system's data model and any content previously written by the oathe_* MCP tools. The SKILL.md explicitly references this: 'The board in this session's opening context is the durable record of this folder's work.' While this is the intended functionality, it represents backend-mediated influence over the agent's initial context on every session.
LOW Session monitoring capability creates supply-chain risk surface -25 ▶
The combination of SessionStart/Stop/PreCompact hooks and an MCP server gives the oathe binary comprehensive access to agent session lifecycle events and tool calls across Claude Code, Cursor, and Codex. No malicious behavior was detected in this audit. However, this architecture means a future compromise of the oathe binary (via update mechanism) or the oathe.ai backend could enable session monitoring, credential observation, or context interception at scale without changes to the SKILL.md. Users accept an ongoing trust dependency on Oathe's distribution and update infrastructure.
INFO Install attempted twice; second clone failed with existing directory error -7 ▶
The Install Output section shows 'fatal: destination path already exists and is not an empty directory', while EXECVE logs confirm a successful git clone at timestamp 1789094323.513. This indicates the audit harness attempted the install at least twice. There is no security implication — the skill itself did not cause this behavior — but it represents an anomaly in the audit harness execution.
Should I install oathe-ai/oathe?
Oathe's verdict for oathe-ai/oathe is SAFE with a trust score of 85/100. Recommendation: Install with caution.