crontap-quickstart

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and workflow guidance for the Crontap service. No malicious commands or scripts are included.
  • [CREDENTIALS_UNSAFE]: The skill explicitly advises against hardcoding credentials, recommending the use of environment variables ($CRONTAP_CLIENT_ID, $CRONTAP_API_KEY) and secret managers. This aligns with security best practices.
  • [EXTERNAL_DOWNLOADS]: The skill references official vendor domains (crontap.com, api.crontap.com) for tool access and documentation. These are legitimate resources owned by the skill's author.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user queries via the list_timezones tool and processes account data via get_account_usage. However, both tools are read-only and do not provide an attack surface for escalating privileges or executing dangerous operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:33 AM
Security Audit — agent-trust-hub — crontap-quickstart