skills/dfinity/icskills/vetkeys/Gen Agent Trust Hub

vetkeys

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE]: The skill provides official documentation and implementation guides for vetKeys cryptography on the Internet Computer, authored by the official vendor DFINITY.
  • [SAFE]: External downloads and package references target established and official platforms for the ecosystem, including npmjs.com, crates.io, and the official Motoko package registry (mops.one).
  • [SAFE]: The instructions include proactive security guidance, such as explicitly warning developers to enforce authorization checks (Pitfall 9) and cautioning against placing sensitive data in plaintext identifiers (Pitfall 7).
  • [SAFE]: Automated scanner alerts for the package registry and the markdown file appear to be false positives or domain reputation issues unrelated to the specific cryptographic content provided in the skill.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 23, 2026, 11:04 PM
Security Audit — agent-trust-hub — vetkeys