narova-stock-extensions
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured workflow for media asset discovery across reputable third-party providers (e.g., NASA, Smithsonian, Wikimedia Commons) and museum collections.
- [CREDENTIALS_SAFE]: The skill correctly references environment variables for required API keys (such as
PEXELS_API_KEYandPIXABAY_API_KEY) instead of hardcoding sensitive credentials. - [DATA_EXPOSURE_SAFE]: Network operations are restricted to the intended purpose of media discovery and acquisition from established providers. The instructions explicitly prohibit bypassing site controls, anti-bot mechanisms, or authentication.
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external websites to retrieve asset metadata and files. While this creates a surface for indirect prompt injection from third-party content, the instructions mitigate this by mandating item-level review, official CLI verification steps (
narova assets verify), and explicit provenance recording.
Audit Metadata