onelogin

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes standard environment variables (APIDECK_API_KEY, APIDECK_APP_ID) for secret management, avoiding hardcoded credentials.
  • [SAFE]: All external URL references and network operations (via curl and SDK examples) target official vendor domains, specifically apideck.com, unify.apideck.com, and developers.apideck.com.
  • [SAFE]: The skill references the official vendor library @apideck/unify for implementation.
  • [SAFE]: No patterns of obfuscation, persistence, privilege escalation, or malicious command execution were detected.
  • [LOW]: Regarding Indirect Prompt Injection, the skill processes data from external HRIS sources (OneLogin). While this constitutes an attack surface, the risk is mitigated by the use of structured API interactions and standard LLM safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 09:16 PM
Security Audit — agent-trust-hub — onelogin