vulnerability-explainer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is restricted to a read-only workflow, specifically prohibiting the agent from editing files, running mutating commands, or performing unauthorized write operations.
  • [SAFE]: Specific instructions are provided to handle configuration files (~/.endorctl/config.yaml) securely by extracting only the namespace identifier and strictly forbidding the display or exfiltration of any credentials, tokens, or secrets.
  • [SAFE]: The skill includes boundary instructions to treat all external data, such as vulnerability records and dependency metadata, as data rather than instructions, mitigating potential indirect prompt injection vulnerabilities.
  • [SAFE]: The skill uses established vendor tools (Endor MCP and endorctl) to perform lookups, ensuring that operations are conducted within the intended architectural scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:47 PM
Security Audit — agent-trust-hub — vulnerability-explainer