skills/402md/skillmd/weather-api/Gen Agent Trust Hub

weather-api

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation references the use of '@402md/mcp' and '@402md/x402' Node.js packages for handling payments and communication. These are vendor-provided libraries intended for the skill's primary purpose.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs developers to manage sensitive credentials, specifically the 'STELLAR_SECRET', using environment variables (e.g., 'process.env.STELLAR_SECRET') rather than hardcoding them into the skill logic.
  • [DATA_EXFILTRATION]: The skill performs network requests to 'api.weatherco.com' to retrieve weather data and to 'facilitator.402.md' for payment processing. These are legitimate operations required for the skill to function as a paid API service.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved from the Weather API.
  • Ingestion points: Data enters the context from 'api.weatherco.com' through the '/v1/current' and '/v1/forecast' endpoints (SKILL.md).
  • Boundary markers: None explicitly defined in the instructions for isolating API output.
  • Capability inventory: The skill performs network requests but does not have file system access or shell execution capabilities.
  • Sanitization: No specific sanitization or filtering of the weather data is described before presentation to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 12:46 PM
Security Audit — agent-trust-hub — weather-api