skills/ericrisco/rsc-harness/make/Gen Agent Trust Hub

make

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill documents best practices for credential management by instructing the agent to read secrets from environment variables rather than hardcoding them (as seen in the .env section of SKILL.md).
  • [COMMAND_EXECUTION]: The skill utilizes standard curl and jq commands to interact with the Make.com REST API. These commands are localized to the documented well-known service infrastructure (make.com) and are standard for the skill's primary purpose of API operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data by retrieving scenario blueprints from the Make.com API. While this introduces a data ingestion surface, the risk is inherent to the skill's primary purpose of managing automation flows, and no malicious exploitation patterns were detected.
  • Ingestion points: REST API endpoints such as GET /scenarios/{id}/blueprint and GET /templates/{id}/blueprint (referenced in SKILL.md and references/blueprint-round-trip.md).
  • Boundary markers: None explicitly defined for API response processing.
  • Capability inventory: Includes capabilities for creating, updating, running, and deleting scenarios via curl network calls.
  • Sanitization: The skill promotes a blueprint 'round-trip' method where JSON payloads are manipulated and re-sent as strings, without explicit sanitization of embedded values.
  • [REMOTE_CODE_EXECUTION]: The skill references the integromat/make-mcp-server but does not include instructions for unverified downloads or automatic execution of remote scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:10 PM
Security Audit — agent-trust-hub — make