crontap-quickstart
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and workflow guidance for the Crontap service. No malicious commands or scripts are included.
- [CREDENTIALS_UNSAFE]: The skill explicitly advises against hardcoding credentials, recommending the use of environment variables ($CRONTAP_CLIENT_ID, $CRONTAP_API_KEY) and secret managers. This aligns with security best practices.
- [EXTERNAL_DOWNLOADS]: The skill references official vendor domains (crontap.com, api.crontap.com) for tool access and documentation. These are legitimate resources owned by the skill's author.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user queries via the
list_timezonestool and processes account data viaget_account_usage. However, both tools are read-only and do not provide an attack surface for escalating privileges or executing dangerous operations.
Audit Metadata