hermes-token-audit
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates a comprehensive 'Untrusted Content Boundary' that instructs the AI agent to treat all ingested data (databases, logs, etc.) as evidence rather than instructions, providing strong protection against indirect prompt injection.
- [SAFE]: No external network operations, remote code execution, or unauthorized data exfiltration patterns were detected. The skill relies on local read-only access to SQLite databases and provider exports.
- [SAFE]: The included Python validation scripts (scripts/validate_bundle.py and tests/test_contracts.py) use only standard libraries and are designed to enforce security and privacy standards, such as checking for hardcoded secrets.
Audit Metadata