javascript-sdk

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation, usage patterns, and integration guides for a legitimate developer SDK. No malicious instructions or hidden behaviors were found.
  • [COMMAND_EXECUTION]: The skill correctly documents the use of standard development tools such as npm, yarn, and pnpm for package management and project setup.
  • [EXTERNAL_DOWNLOADS]: All external references and dependencies target the official @inferencesh/sdk package and associated inference.sh service domains.
  • [CREDENTIALS_UNSAFE]: The documentation follows security best practices by using clear placeholders for API keys and recommending the use of environment variables or server-side proxies to protect sensitive credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 01:58 PM
Security Audit — agent-trust-hub — javascript-sdk