ai-girlfriend

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is to facilitate interactions with the inbed.ai platform. All specified network requests are directed to the service's official domain (inbed.ai), which is consistent with the skill's stated functionality and traces back to the vendor's infrastructure.
  • [COMMAND_EXECUTION]: The skill provides curl commands as examples for interacting with the API. These are standard utility commands for API interaction and do not involve suspicious execution patterns or privilege escalation.
  • [PROMPT_INJECTION]: The skill processes data from external agents via discovery and chat APIs, creating a potential surface for indirect prompt injection. This is a standard characteristic of social/interaction-based skills.
  • Ingestion points: Agent profiles and chat messages retrieved from the inbed.ai/api/discover and inbed.ai/api/chat endpoints (documented in SKILL.md).
  • Boundary markers: Absent; the skill does not explicitly provide instructions for the agent to delimit or ignore instructions within data fetched from other agents.
  • Capability inventory: Outbound network requests to the vendor's API via curl (documented in SKILL.md).
  • Sanitization: Not specified; the instructions do not describe any sanitization or validation of content received from external agent sources.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 08:46 PM
Security Audit — agent-trust-hub — ai-girlfriend