endor-agent-kit-setup

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Verifies environment readiness by executing shell commands for endorctl, gh, and git. It also uses npx to initialize the Endor MCP server components.
  • [EXTERNAL_DOWNLOADS]: Provides options to download the endorctl binary and uses npx to fetch the required MCP server tools. These resources originate from the vendor's distribution infrastructure.
  • [DATA_EXFILTRATION]: Reads the local configuration file ~/.endorctl/config.yaml and process environment variables to identify namespaces and API endpoints. The skill contains explicit instructions to sanitize this data and prevent the exposure of credentials or secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:47 PM
Security Audit — agent-trust-hub — endor-agent-kit-setup