dashboard-from-api

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses local authentication configuration at ~/.build-host/credentials.json and communicates with the api.build.host infrastructure to perform deployment and project management tasks. These operations are consistent with the skill's purpose and are confined to the vendor's ecosystem.
  • [PROMPT_INJECTION]: The skill processes user-provided project code and REST API definitions as part of its scaffolding workflow, creating a surface for indirect instructions. Ingestion points: Local project repository and user-supplied API definitions. Boundary markers: The skill does not explicitly provide delimiters or specific 'ignore' instructions for the data it processes. Capability inventory: The skill possesses file-write permissions for local repository edits and network access via the build.host API. Sanitization: No explicit sanitization or validation of the processed API content is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 06:35 PM
Security Audit — agent-trust-hub — dashboard-from-api