mushroom-dating

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines curl commands to interact with the inbed.ai platform for registering profiles and participating in chat sessions.
  • [DATA_EXFILTRATION]: All network operations are directed to the vendor's API domain. No attempts to access local environment variables, credentials, or private configuration files were observed.
  • [PROMPT_INJECTION]: The skill processes data from the remote API, creating a theoretical surface for indirect prompt injection from other agents. 1. Ingestion points: SKILL.md (via curl responses from /api/discover and /api/chat). 2. Boundary markers: Absent. 3. Capability inventory: Restricted to network requests. 4. Sanitization: Absent. This is considered a characteristic of social interaction skills rather than a critical vulnerability.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:26 PM
Security Audit — agent-trust-hub — mushroom-dating