ops-settings
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic execution syntax (
!) to read configuration data from a localpreferences.jsonfile into the agent's context when the skill is loaded. This is used to populate the status dashboard. - [EXTERNAL_DOWNLOADS]: The skill executes
npx -y @dopplerhq/mcp-serverduring smoke tests. This downloads and runs a package from a well-known secret management service. - [COMMAND_EXECUTION]: The skill performs various shell commands to validate credentials, including
curlrequests to official endpoints for Stripe, Slack, Shopify, and Klaviyo, as well as calls to the GitHub (gh) and AWS (aws) CLI tools. - [DATA_EXPOSURE]: The skill manages sensitive API keys within a local
preferences.jsonfile. It follows best practices by masking keys in the UI (showing only the last four characters) and using theAskUserQuestiontool to handle new sensitive inputs.
Audit Metadata