brave-search

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @aiagenta2z/onekey-gateway npm package and the ai-agent-marketplace Python package. These are official vendor-maintained resources required to interface with the OneKey Gateway service.
  • [CREDENTIALS_UNSAFE]: The scripts contain a hardcoded fallback API key BETA_TEST_KEY_MARCH_2026. This is explicitly documented as a demo/test key for use when the DEEPNLP_ONEKEY_ROUTER_ACCESS environment variable is not configured.
  • [COMMAND_EXECUTION]: The skill includes instructions for running tools via the npx onekey CLI or Python scripts. These executions are limited to passing search parameters to the vendor's API gateway and do not involve arbitrary shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:40 PM
Security Audit — agent-trust-hub — brave-search