node-red-automation

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation and templates for building legitimate Node-RED automations.
  • [EXTERNAL_DOWNLOADS]: References official Node-RED software and standard plugins from the npm registry.
  • [COMMAND_EXECUTION]: Includes routine shell commands for installation and running services via npm.
  • [CREDENTIALS_UNSAFE]: Includes settings.js templates with placeholders for password hashes and SSL certificate paths.
  • [PROMPT_INJECTION]: The skill provides templates for processing external data from MQTT, HTTP, and Home Assistant. Ingestion points: MQTT In, HTTP In, HA Events (SKILL.md). Boundary markers: Absent. Capability inventory: Service calls, HTTP requests (SKILL.md). Sanitization: Minimal.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 11:09 AM
Security Audit — agent-trust-hub — node-red-automation