discover-product-domain

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured multi-step process for domain discovery and verification. It explicitly states that registrar interactions are read-only and prohibits any mutation or purchase operations (sign-in, cart, etc.).
  • [EXTERNAL_DOWNLOADS]: The skill uses registry RDAP lookups and the Namecheap API for domain verification. These are legitimate, well-known services for the skill's stated purpose and do not represent a security risk.
  • [DATA_EXPOSURE]: The skill instructs the agent to redact credential-bearing request URLs if they exist, following security best practices.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied names and ideas, its capabilities are strictly limited to domain lookups and local report generation. It does not execute remote code based on user input or access sensitive system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 04:18 PM
Security Audit — agent-trust-hub — discover-product-domain