malware-response

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the 'endorctl' CLI tool to query the Endor Labs platform. It provides a specific read-only query recipe for fetching package version evidence and specifies that shell commands must stay read-only and match documented lookup shapes.
  • [SAFE]: The skill is authored by the vendor (endorlabs) and is intended to interact with their own ecosystem. It includes robust security mitigations, such as a strict 'read-only' constraint, instructions to treat external intelligence as data rather than executable instructions, and explicit rules against echoing credentials or secrets from configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:47 PM
Security Audit — agent-trust-hub — malware-response