freee-api-skill
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by the vendor and exclusively interacts with official freee services. A review of all 102 files found no evidence of malicious instructions or behavior.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the vendor's official remote MCP server at
https://mcp.freee.co.jp/mcpand encourages the installation of the officialfreee-mcppackage from the NPM registry. - [COMMAND_EXECUTION]: Instructions provide guidance for running the vendor's configuration command (
npx freee-mcp configure), which is the standard setup procedure for this tool. - [PROMPT_INJECTION]: The skill has an architectural surface for indirect prompt injection as it ingests data from API responses and possesses record modification capabilities (e.g.,
freee_api_post,freee_api_delete). While no explicit boundary markers or sanitization logic are defined in the instructions, this is an inherent risk of the tool's primary purpose and is managed by the agent's internal safety protocols.
Audit Metadata