weather-api
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation references the use of '@402md/mcp' and '@402md/x402' Node.js packages for handling payments and communication. These are vendor-provided libraries intended for the skill's primary purpose.
- [CREDENTIALS_UNSAFE]: The skill correctly instructs developers to manage sensitive credentials, specifically the 'STELLAR_SECRET', using environment variables (e.g., 'process.env.STELLAR_SECRET') rather than hardcoding them into the skill logic.
- [DATA_EXFILTRATION]: The skill performs network requests to 'api.weatherco.com' to retrieve weather data and to 'facilitator.402.md' for payment processing. These are legitimate operations required for the skill to function as a paid API service.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved from the Weather API.
- Ingestion points: Data enters the context from 'api.weatherco.com' through the '/v1/current' and '/v1/forecast' endpoints (SKILL.md).
- Boundary markers: None explicitly defined in the instructions for isolating API output.
- Capability inventory: The skill performs network requests but does not have file system access or shell execution capabilities.
- Sanitization: No specific sanitization or filtering of the weather data is described before presentation to the user.
Audit Metadata