hexabot-action-creator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for credential handling, explicitly advising against hardcoding secrets and recommending the use of credential references via the platform's internal services (context.services.credentials).
  • [SAFE]: All external resource references, such as NPM packages (@hexabot-ai/agentic, @hexabot-ai/api), are official vendor resources belonging to the skill author (hexabot-ai).
  • [SAFE]: The skill provides clear instructions for input validation using Zod schemas to ensure data integrity in generated actions, reducing the surface for indirect prompt injection and malformed data processing.
  • [SAFE]: No obfuscation, prompt injection, or unauthorized remote code execution patterns were found. Guidelines for logging explicitly mention redacting sensitive information such as tokens and customer records.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:42 PM
Security Audit — agent-trust-hub — hexabot-action-creator