step-parts

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches part metadata and STEP files from the vendor's API at api.step.parts and static assets from www.step.parts. This behavior is documented and central to the skill's purpose.\n- [COMMAND_EXECUTION]: The skill executes a local Python script (scripts/download_step_part.py) to manage the search and download workflow. This script is self-contained, uses only standard library modules, and implements checksum validation for all downloaded files.\n- [SAFE]: No malicious patterns such as prompt injection, sensitive data exfiltration, obfuscation, or persistence mechanisms were detected in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:27 AM
Security Audit — agent-trust-hub — step-parts