endor-check

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to provide security information about software packages. It utilizes specific MCP tools (check_dependency_for_risks and check_dependency_for_vulnerabilities) to query the Endor Labs database.
  • [SAFE]: Analysis of the workflow and input parsing logic shows no evidence of prompt injection, data exfiltration, or unauthorized command execution. The skill operates within the expected scope of a security auditing tool.
  • [SAFE]: There are no hardcoded credentials, obfuscated strings, or attempts to access sensitive system files. All external references and commands are consistent with the vendor's (Endor Labs) official ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 04:25 AM