managing-spot-io
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell scripts to interact with the Spot.io API via
curl. These operations are transparent, target official API endpoints (https://api.spotinst.io), and are intended for the skill's primary purpose of cloud infrastructure management. - [DATA_EXFILTRATION]: While the skill makes network requests using an authentication token (
$SPOT_TOKEN), these requests are strictly directed to the official Spot.io API and are necessary for the skill's functionality. There is no evidence of sensitive data being sent to unauthorized third-party domains. - [CREDENTIALS_UNSAFE]: The skill correctly uses an environment variable (
$SPOT_TOKEN) for authentication rather than hardcoding secrets, following security best practices.
Audit Metadata