atypica-research
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes
scripts/mcp-call.sh, a bash utility that usescurlandjqto interact with the atypica.ai API. This is documented as a fallback for environments without MCP support and performs standard HTTP requests to the vendor's endpoint. - [DATA_EXFILTRATION]: All network operations are directed to
atypica.ai, the official domain of the skill vendor. No evidence of sensitive local file access or unauthorized data transmission to third-party domains was found. - [CREDENTIALS_UNSAFE]: The documentation follows security best practices by instructing users to manage API keys via environment variables or secure configuration files rather than hardcoding them.
- [PROMPT_INJECTION]: Instructions are focused on technical implementation and research workflows. No patterns attempting to bypass safety filters or override agent behavior were identified.
Audit Metadata