privacy-cards

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes use of shell commands including curl for API communication and python3 for JSON processing. These operations are restricted to the intended business logic of the skill.
  • [DATA_EXFILTRATION]: The skill manages sensitive cardholder data but incorporates specific instructions and code snippets designed to avoid logging this data to chat or unauthorized sinks. Network operations target well-known Privacy.com API endpoints.
  • [CREDENTIALS_UNSAFE]: The skill uses environment variables for secret management, adhering to security best practices by not hardcoding sensitive API keys.
  • [SAFE]: No evidence of prompt injection, persistence mechanisms, or obfuscation was found. The skill's functionality is transparent and matches its documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 05:38 AM