privacy-cards
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes use of shell commands including
curlfor API communication andpython3for JSON processing. These operations are restricted to the intended business logic of the skill. - [DATA_EXFILTRATION]: The skill manages sensitive cardholder data but incorporates specific instructions and code snippets designed to avoid logging this data to chat or unauthorized sinks. Network operations target well-known Privacy.com API endpoints.
- [CREDENTIALS_UNSAFE]: The skill uses environment variables for secret management, adhering to security best practices by not hardcoding sensitive API keys.
- [SAFE]: No evidence of prompt injection, persistence mechanisms, or obfuscation was found. The skill's functionality is transparent and matches its documentation.
Audit Metadata