skills/agnostai/skills/agnost-ai/Gen Agent Trust Hub

agnost-ai

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates automated instrumentation of local source code. It modifies project files including package.json, requirements.txt, and .env to incorporate vendor-specific dependencies and configuration parameters.
  • [SAFE]: Network operations are restricted to the vendor's official endpoints (api.agnost.ai, otel.agnost.ai) for organization provisioning and telemetry verification. The scripts also support local development endpoints.
  • [SAFE]: All identified software dependencies, such as agnost, agnostai, and agnost-mcp, are vendor resources associated with 'agnostai'. Other referenced libraries are well-known open-source SDKs and OpenTelemetry packages.
  • [SAFE]: Code modification logic in scripts/instrument.mjs is designed to inject initialization code for recognized AI frameworks (e.g., Vercel AI SDK, Mastra, MCP servers). These actions are necessary for the skill's primary function and focus on adding telemetry handlers.
  • [SAFE]: The skill follows security best practices by explicitly warning against logging raw bearer tokens and using environment variables for sensitive configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 08:02 PM
Security Audit — agent-trust-hub — agnost-ai