duffel

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts exclusively with the official Duffel API domain (api.duffel.com) to perform flight searches.
  • [SAFE]: API credentials are managed securely via environment variables (DUFFEL_API_KEY_LIVE) rather than being hardcoded within the instructions.
  • [SAFE]: The use of curl for network requests and jq for JSON processing is standard and appropriate for the skill's stated purpose.
  • [SAFE]: No obfuscation, persistence mechanisms, or unauthorized privilege escalation patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 11:26 AM
Security Audit — agent-trust-hub — duffel