epds-login
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides diagnostic bash commands to assist developers in verifying their OAuth configuration.\n
- Evidence: Verification steps in
SKILL.mdusecurlto inspect discovery and metadata endpoints.\n- [EXTERNAL_DOWNLOADS]: The skill instructions demonstrate how to fetch JSON configuration files from the application's own endpoints.\n - Evidence: Example
curlcommands target placeholder URLs likehttps://yourapp.example.com/client-metadata.json.\n- [REMOTE_CODE_EXECUTION]: Automated alerts flagged pipes topython3as a security risk. Analysis shows these are safe uses of the built-injson.toolmodule for pretty-printing data.\n - Analysis: The command
python3 -m json.toolis a data-processing utility and does not provide an execution environment for arbitrary scripts. The source URLs are placeholders representing the developer's own server.
Audit Metadata