skills/bounded-sh/skill/oapps-fun/Gen Agent Trust Hub

oapps-fun

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Instructions guide the user to execute platform-specific CLI commands (such as bounded init, bounded deploy, and bounded oapp preflight) to manage application lifecycle and security validation.
  • [EXTERNAL_DOWNLOADS]: The skill describes a build process (npm run build) that typically involves downloading dependencies from public registries and utilizes an 'x402 relay' mechanism for making authenticated HTTP requests to external services without exposing secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building AI-driven applications that ingest external data. It addresses this risk surface by mandating a 'zero-secrets' architecture, strict 'boundaries' definitions, and automated security preflights to ensure no individual creator holds privileged levers over the launched app.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 06:35 PM
Security Audit — agent-trust-hub — oapps-fun