make
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill documents best practices for credential management by instructing the agent to read secrets from environment variables rather than hardcoding them (as seen in the
.envsection ofSKILL.md). - [COMMAND_EXECUTION]: The skill utilizes standard
curlandjqcommands to interact with the Make.com REST API. These commands are localized to the documented well-known service infrastructure (make.com) and are standard for the skill's primary purpose of API operation. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data by retrieving scenario blueprints from the Make.com API. While this introduces a data ingestion surface, the risk is inherent to the skill's primary purpose of managing automation flows, and no malicious exploitation patterns were detected.
- Ingestion points: REST API endpoints such as
GET /scenarios/{id}/blueprintandGET /templates/{id}/blueprint(referenced inSKILL.mdandreferences/blueprint-round-trip.md). - Boundary markers: None explicitly defined for API response processing.
- Capability inventory: Includes capabilities for creating, updating, running, and deleting scenarios via
curlnetwork calls. - Sanitization: The skill promotes a blueprint 'round-trip' method where JSON payloads are manipulated and re-sent as strings, without explicit sanitization of embedded values.
- [REMOTE_CODE_EXECUTION]: The skill references the
integromat/make-mcp-serverbut does not include instructions for unverified downloads or automatic execution of remote scripts.
Audit Metadata