subgraph-doctor

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts exclusively with the official Goldsky ecosystem, including the goldsky CLI and the @goldskycom/cli NPM package. All external resources align with the vendor's identity (goldsky-io).
  • [COMMAND_EXECUTION]: The skill uses shell commands to manage subgraphs via the goldsky CLI. These commands include list, log, start, pause, deploy, and delete, which are standard for the tool's intended use.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data transfer or exfiltration to non-whitelisted domains was found. Access is limited to project data and logs required for diagnostics.
  • [PROMPT_INJECTION]: The skill handles subgraph logs, which constitute a surface for indirect prompt injection. However, the instructions constrain the agent to diagnostic parsing and error identification, minimizing the risk of instructions in data being obeyed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:42 PM
Security Audit — agent-trust-hub — subgraph-doctor