ops-settings

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic execution syntax (!) to read configuration data from a local preferences.json file into the agent's context when the skill is loaded. This is used to populate the status dashboard.
  • [EXTERNAL_DOWNLOADS]: The skill executes npx -y @dopplerhq/mcp-server during smoke tests. This downloads and runs a package from a well-known secret management service.
  • [COMMAND_EXECUTION]: The skill performs various shell commands to validate credentials, including curl requests to official endpoints for Stripe, Slack, Shopify, and Klaviyo, as well as calls to the GitHub (gh) and AWS (aws) CLI tools.
  • [DATA_EXPOSURE]: The skill manages sensitive API keys within a local preferences.json file. It follows best practices by masking keys in the UI (showing only the last four characters) and using the AskUserQuestion tool to handle new sensitive inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:54 PM