algolia-release-qa

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions emphasize security best practices, specifically flagging the exposure of admin-capable API keys as a 'Blocker' issue.
  • [SAFE]: Data exfiltration risks are mitigated by the explicit instruction not to use the skill for inspecting live account data or making live account changes, directing users to official CLI and MCP tools instead.
  • [SAFE]: All external documentation and learning links point to official Algolia domains (algolia.com, academy.algolia.com).
  • [SAFE]: Indirect prompt injection risks are managed through the requirement of an 'evidence matrix' and 'readiness signposts,' which forces the agent to rely on verifiable data rather than potentially malicious user-provided screenshots or code snippets.
  • [SAFE]: The skill includes comprehensive checklists for regression, relevance, and event attribution, ensuring that AI-driven features like NeuralSearch have verified prerequisites before launch.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 02:36 AM
Security Audit — agent-trust-hub — algolia-release-qa