trinet

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill adheres to security best practices by using environment variables (process.env.APIDECK_API_KEY, process.env.APIDECK_APP_ID) for authentication, avoiding hardcoded secrets.
  • [DATA_EXFILTRATION]: Network operations are directed to unify.apideck.com and specs.apideck.com, which are official endpoints for the Apideck service infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill references the @apideck/unify library and official OpenAPI specifications from the vendor's trusted domains.
  • [SAFE]: The skill acts as a data ingestion surface by fetching employee and payroll data from TriNet via Apideck. While this is an indirect prompt injection surface, the skill does not possess exploitable capabilities (like file writes or shell execution) that could be abused by malicious data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 11:01 AM
Security Audit — agent-trust-hub — trinet