skills/alapi-sdk/skill/alapi/Gen Agent Trust Hub

alapi

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script (scripts/alapi.py) to handle API discovery and interactions. This script is implemented using standard libraries and follows the agent's command-line execution patterns.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with official ALAPI vendor domains (v3.alapi.cn and www.alapi.cn) to retrieve API specifications and documentation. These network operations are strictly bound to the vendor's own infrastructure and are essential for the skill's purpose.
  • [SAFE]: The skill demonstrates proactive security by instructing the agent to prioritize environment variables for tokens and explicitly prohibiting the disclosure of credentials in final responses. No signs of obfuscation, persistence, or malicious behavior were found during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 08:48 AM
Security Audit — agent-trust-hub — alapi