findings-browser

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly read-only and explicitly prohibits any mutating actions such as scanning, writing to repositories, or modifying Endor Labs state.
  • [SAFE]: Implements a robust namespace preflight process to ensure data is accessed from the correct and authorized context.
  • [SAFE]: Includes explicit instructions to treat finding titles, descriptions, and metadata as untrusted data to prevent prompt injection from processed content.
  • [SAFE]: Shell command usage is restricted to read-only lookups via endorctl api with specific field masks to avoid echoing sensitive information like secrets or credential keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:47 PM
Security Audit — agent-trust-hub — findings-browser