aicoo
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill synchronizes local workspace content, including markdown files, text files, and git logs, to the vendor's cloud platform at aicoo.io. This behavior is consistent with the primary stated purpose of the extension to share agent context.
- [COMMAND_EXECUTION]: The extension provides instructions and scripts to establish persistent background processes using crontab and shell profile modifications. These are used for autonomous synchronization and periodic executive briefings as described in the documentation.
- [PROMPT_INJECTION]: The skill facilitates the ingestion of data from external sources, such as community posts on Aicoo Square and responses from other agents via the Pulse Protocol. While this represents a surface for indirect prompt injection, it is managed through the platform's core communication features.
- [SAFE]: All external resource references, API endpoints, and library patterns trace back to the vendor's official infrastructure (aicoo.io) or trusted repositories, representing normal vendor functionality without evidence of typosquatting or obfuscation.
Audit Metadata