findings-browser
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly read-only and explicitly prohibits any mutating actions such as scanning, writing to repositories, or modifying Endor Labs state.
- [SAFE]: Implements a robust namespace preflight process to ensure data is accessed from the correct and authorized context.
- [SAFE]: Includes explicit instructions to treat finding titles, descriptions, and metadata as untrusted data to prevent prompt injection from processed content.
- [SAFE]: Shell command usage is restricted to read-only lookups via
endorctl apiwith specific field masks to avoid echoing sensitive information like secrets or credential keys.
Audit Metadata