cohere-upgrade-migration

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository code and configuration to perform its migration tasks, which naturally involves reading untrusted local data. This surface is inherent to the skill's primary purpose and is well-mitigated by robust instructions for data handling.
  • Ingestion points: Target repository files and configuration data accessed via Read, Glob, and Grep tools.
  • Boundary markers: Explicit instructions to redact sensitive information and maintain strict approval boundaries for production-impacting actions.
  • Capability inventory: The skill utilizes Read, Write, Edit, and WebFetch tools for migration and documentation lookup.
  • Sanitization: Instructions specifically mandate the redaction of API keys, authorization headers, and customer identifiers in all outputs.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and reference files point to official documentation, SDK repositories, and package registries for Cohere. These references target a well-known technology service and are appropriate for the migration task.
  • Package references: Mentions official SDK versions cohere-ai@8.1.0 and cohere==7.1.1 in the context of registry releases.
  • Trusted sources: All URLs point to established domains under cohere.com and official GitHub repositories under the cohere-ai organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:15 PM
Security Audit — agent-trust-hub — cohere-upgrade-migration