endor-check
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to provide security information about software packages. It utilizes specific MCP tools (check_dependency_for_risks and check_dependency_for_vulnerabilities) to query the Endor Labs database.
- [SAFE]: Analysis of the workflow and input parsing logic shows no evidence of prompt injection, data exfiltration, or unauthorized command execution. The skill operates within the expected scope of a security auditing tool.
- [SAFE]: There are no hardcoded credentials, obfuscated strings, or attempts to access sensitive system files. All external references and commands are consistent with the vendor's (Endor Labs) official ecosystem.
Audit Metadata