skills/hypercerts-org/epds/epds-login/Gen Agent Trust Hub

epds-login

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides diagnostic bash commands to assist developers in verifying their OAuth configuration.\n
  • Evidence: Verification steps in SKILL.md use curl to inspect discovery and metadata endpoints.\n- [EXTERNAL_DOWNLOADS]: The skill instructions demonstrate how to fetch JSON configuration files from the application's own endpoints.\n
  • Evidence: Example curl commands target placeholder URLs like https://yourapp.example.com/client-metadata.json.\n- [REMOTE_CODE_EXECUTION]: Automated alerts flagged pipes to python3 as a security risk. Analysis shows these are safe uses of the built-in json.tool module for pretty-printing data.\n
  • Analysis: The command python3 -m json.tool is a data-processing utility and does not provide an execution environment for arbitrary scripts. The source URLs are placeholders representing the developer's own server.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:16 PM
Security Audit — agent-trust-hub — epds-login