hexabot-action-creator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices for credential handling, explicitly advising against hardcoding secrets and recommending the use of credential references via the platform's internal services (context.services.credentials).
- [SAFE]: All external resource references, such as NPM packages (@hexabot-ai/agentic, @hexabot-ai/api), are official vendor resources belonging to the skill author (hexabot-ai).
- [SAFE]: The skill provides clear instructions for input validation using Zod schemas to ensure data integrity in generated actions, reducing the surface for indirect prompt injection and malformed data processing.
- [SAFE]: No obfuscation, prompt injection, or unauthorized remote code execution patterns were found. Guidelines for logging explicitly mention redacting sensitive information such as tokens and customer records.
Audit Metadata