expanso-fan-out-pattern

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill files. The skill correctly implements a data routing pattern using a specific tool configuration.
  • [COMMAND_EXECUTION]: The provided shell scripts (run.sh and test.sh) are used for legitimate administrative tasks. run.sh executes the expanso command to start the pipeline, and test.sh performs syntax validation of the configuration file using common tools like yq or python3.
  • [EXTERNAL_DOWNLOADS]: The documentation points to the official expanso.io domain for further resources and mentions clawhub for tool installation, which is standard practice for the vendor's ecosystem.
  • [DATA_EXFILTRATION]: The pipeline is designed to transmit data to external services (AWS S3, Kafka, Elasticsearch). This behavior is the primary purpose of the skill and is securely implemented by referencing environment variables for endpoints and credentials rather than hardcoding sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 05:45 AM
Security Audit — agent-trust-hub — expanso-fan-out-pattern