oapps-fun
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Instructions guide the user to execute platform-specific CLI commands (such as
bounded init,bounded deploy, andbounded oapp preflight) to manage application lifecycle and security validation. - [EXTERNAL_DOWNLOADS]: The skill describes a build process (
npm run build) that typically involves downloading dependencies from public registries and utilizes an 'x402 relay' mechanism for making authenticated HTTP requests to external services without exposing secrets. - [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building AI-driven applications that ingest external data. It addresses this risk surface by mandating a 'zero-secrets' architecture, strict 'boundaries' definitions, and automated security preflights to ensure no individual creator holds privileged levers over the launched app.
Audit Metadata