vulnerability-explainer
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is restricted to a read-only workflow, specifically prohibiting the agent from editing files, running mutating commands, or performing unauthorized write operations.
- [SAFE]: Specific instructions are provided to handle configuration files (~/.endorctl/config.yaml) securely by extracting only the namespace identifier and strictly forbidding the display or exfiltration of any credentials, tokens, or secrets.
- [SAFE]: The skill includes boundary instructions to treat all external data, such as vulnerability records and dependency metadata, as data rather than instructions, mitigating potential indirect prompt injection vulnerabilities.
- [SAFE]: The skill uses established vendor tools (Endor MCP and endorctl) to perform lookups, ensuring that operations are conducted within the intended architectural scope.
Audit Metadata