freee-api-skill

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by the vendor and exclusively interacts with official freee services. A review of all 102 files found no evidence of malicious instructions or behavior.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the vendor's official remote MCP server at https://mcp.freee.co.jp/mcp and encourages the installation of the official freee-mcp package from the NPM registry.
  • [COMMAND_EXECUTION]: Instructions provide guidance for running the vendor's configuration command (npx freee-mcp configure), which is the standard setup procedure for this tool.
  • [PROMPT_INJECTION]: The skill has an architectural surface for indirect prompt injection as it ingests data from API responses and possesses record modification capabilities (e.g., freee_api_post, freee_api_delete). While no explicit boundary markers or sanitization logic are defined in the instructions, this is an inherent risk of the tool's primary purpose and is managed by the agent's internal safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 06:21 AM