skills/delorenj/skills/agno/Gen Agent Trust Hub

agno

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation contains examples for installing the Agno framework and its dependencies from official registries (PyPI, NPM) and using tools like uvx and npx to run MCP servers from known organizations such as the Model Context Protocol team.
  • [COMMAND_EXECUTION]: The framework examples demonstrate usage of MCPTools to execute local processes and commands (e.g., uvx mcp-server-git, npx @openbnb/mcp-server-airbnb). These are documented features intended to allow agents to interact with local development tools and services.
  • [INDIRECT_PROMPT_INJECTION]: The framework provides capabilities for agents to ingest untrusted data from the web (via DuckDuckGo, Apify, or web crawlers). The documentation explicitly addresses this risk by detailing built-in security features such as PromptInjectionGuardrail and PIIDetectionGuardrail to help developers mitigate these attacks.
  • [CREDENTIALS_UNSAFE]: The documentation and code examples use standard placeholders for API keys and database credentials (e.g., xxx, YOUR_API_KEY_HERE, user:pass). These are used correctly in instructional context to show developers where to provide their own secrets via environment variables or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:55 PM
Security Audit — agent-trust-hub — agno