b2b-cold-email

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected.
  • [CREDENTIALS_SAFE]: The skill correctly instructs the user/agent to store API keys in environment variables (INSTANTLY_API_KEY) and explicitly warns against hardcoding secrets.
  • [COMMAND_EXECUTION]: Provides standard curl and Python requests snippets for API interaction. Importantly, it includes a safety constraint prohibiting the agent from automatically activating campaigns, requiring manual user intervention for high-risk actions.
  • [EXTERNAL_DOWNLOADS]: Interacts only with the official Instantly.ai API domain (api.instantly.ai), which is a well-known and expected service for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 06:46 AM
Security Audit — agent-trust-hub — b2b-cold-email