skills/edwinhu/workflows/dewey/Gen Agent Trust Hub

dewey

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by explicitly forbidding the hardcoding of API keys and recommending secure storage in environment variables (DEWEY_API_KEY) or restricted local files (~/.config/dewey/apikey).
  • [EXTERNAL_DOWNLOADS]: Facilitates access to academic datasets from official Dewey Data endpoints (downloads.deweydata.io). This is the primary function of the skill and uses vendor-controlled infrastructure for data delivery.
  • [COMMAND_EXECUTION]: Provides standard commands for environment setup and tool usage via pip, uvx, and the dewey CLI. All instructions are transparent and directly support the skill's stated research purpose.
  • [REMOTE_CODE_EXECUTION]: Includes dependencies from official vendor repositories on GitHub (github.com/Dewey-Data). These are legitimate software components necessary for integration with the Dewey Data marketplace.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:30 AM
Security Audit — agent-trust-hub — dewey