endor-scan

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to dynamically download and execute the endorctl package from the official npm registry. This is the official tool provided by the vendor for the skill's stated purpose.- [COMMAND_EXECUTION]: The skill provides instructions for running security scans via the endorctl CLI, specifically using the scan command with flags for dependencies, SAST, and secrets. These operations are restricted to the local repository path.- [DATA_EXPOSURE]: The skill reads repository manifest files (such as package.json, go.mod, pom.xml) to identify project dependencies. This is a standard and necessary function for a vulnerability scanner.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 04:25 AM