managing-spot-io

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell scripts to interact with the Spot.io API via curl. These operations are transparent, target official API endpoints (https://api.spotinst.io), and are intended for the skill's primary purpose of cloud infrastructure management.
  • [DATA_EXFILTRATION]: While the skill makes network requests using an authentication token ($SPOT_TOKEN), these requests are strictly directed to the official Spot.io API and are necessary for the skill's functionality. There is no evidence of sensitive data being sent to unauthorized third-party domains.
  • [CREDENTIALS_UNSAFE]: The skill correctly uses an environment variable ($SPOT_TOKEN) for authentication rather than hardcoding secrets, following security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 11:54 AM
Security Audit — agent-trust-hub — managing-spot-io