floor10-submit

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes curl commands to interact with the vendor's API endpoints at immersivecommons.com. These operations are transparently defined and strictly scoped to the intended functionality of fetching event data, uploading images, and submitting finalized highlight stories.
  • [EXTERNAL_DOWNLOADS]: The installation instructions guide the user to download the skill's source file from the official vendor domain. This is a standard and safe deployment method for this type of extension.
  • [CREDENTIALS_UNSAFE]: Authenticated requests are managed using a user-provided agent token (FLOOR10_AGENT_TOKEN). The skill instructions correctly advise users on setting this token in their local environment, and it is transmitted only to the authoritative vendor platform.
  • [DATA_EXFILTRATION]: Analysis of the skill's network operations confirms that all data transmissions are directed to the vendor's infrastructure for the purpose of processing user-approved submissions. No unauthorized or suspicious data transfer patterns were detected.
  • [PROMPT_INJECTION]: The skill includes robust safeguards against indirect prompt injection from external metadata sources by requiring mandatory human review and explicit approval of all drafted content before submission.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 04:23 AM
Security Audit — agent-trust-hub — floor10-submit