crontap-schedule-http-job

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill performs network operations to 'api.crontap.com' and 'crontap.com', which are the official domains belonging to the skill's author. It explicitly instructs users to keep credentials out of URLs and logs, recommending the use of secure stores and placeholders for sensitive information like Authorization headers.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as URLs, request headers, and bodies to create schedules. While this constitutes an attack surface for processing untrusted data, the skill includes verification steps and instructions for the agent to confirm endpoint outcomes and handle inputs explicitly, which aligns with safe operational practices for a scheduling tool.
  • [COMMAND_EXECUTION]: The skill provides documentation for a REST fallback using curl. These are provided as static examples for the user to understand the API structure and do not involve the agent executing arbitrary or unreviewed shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:33 AM
Security Audit — agent-trust-hub — crontap-schedule-http-job