narova-stock-extensions

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured workflow for media asset discovery across reputable third-party providers (e.g., NASA, Smithsonian, Wikimedia Commons) and museum collections.
  • [CREDENTIALS_SAFE]: The skill correctly references environment variables for required API keys (such as PEXELS_API_KEY and PIXABAY_API_KEY) instead of hardcoding sensitive credentials.
  • [DATA_EXPOSURE_SAFE]: Network operations are restricted to the intended purpose of media discovery and acquisition from established providers. The instructions explicitly prohibit bypassing site controls, anti-bot mechanisms, or authentication.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external websites to retrieve asset metadata and files. While this creates a surface for indirect prompt injection from third-party content, the instructions mitigate this by mandating item-level review, official CLI verification steps (narova assets verify), and explicit provenance recording.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:40 AM
Security Audit — agent-trust-hub — narova-stock-extensions