malware-response
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the 'endorctl' CLI tool to query the Endor Labs platform. It provides a specific read-only query recipe for fetching package version evidence and specifies that shell commands must stay read-only and match documented lookup shapes.
- [SAFE]: The skill is authored by the vendor (endorlabs) and is intended to interact with their own ecosystem. It includes robust security mitigations, such as a strict 'read-only' constraint, instructions to treat external intelligence as data rather than executable instructions, and explicit rules against echoing credentials or secrets from configuration files.
Audit Metadata