referencer

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill manages authentication credentials by storing them in a local configuration file and transmitting them to a remote API for legitimate service interaction.
  • Evidence: scripts/referencer.mjs implements credential persistence in ~/.referencer.toml and network transmission to https://api.referencer.ai/graphql.
  • Security Mitigations: The runner script explicitly redacts API keys from console output and error messages using a dedicated redactKey function. Additionally, the configuration file is created with 0600 permissions (owner read/write only), ensuring it is protected from other users on the system.
  • [PROMPT_INJECTION]: The skill processes structured data from the remote Referencer GraphQL service, which constitutes an attack surface for indirect prompt injection if the service returns malicious content.
  • Ingestion points: Data is received as structured JSON payloads from the Referencer API in scripts/referencer.mjs.
  • Capability inventory: The skill can read and write its own configuration file and perform network requests to the Referencer API.
  • Boundary markers: The skill does not use specific boundary markers or instructions to the agent to ignore embedded content when processing remote data.
  • Sanitization: Data is handled as structured JSON, reducing the risk of accidental execution compared to raw text processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 02:27 AM
Security Audit — agent-trust-hub — referencer