fathom-common-errors

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes benign curl commands for testing API status and webhook functionality. These are standard diagnostic tools and do not involve piping to shells or execution of untrusted remote content.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No credentials are hardcoded. The diagnostic command correctly references ${FATHOM_API_KEY}, adhering to safe secret management practices. Network requests are directed to the official Fathom API domain (api.fathom.ai).
  • [SAFE]: The instructions explicitly direct the agent to collect only "opaque IDs," use "redacted evidence," and test fixes with "synthetic records," demonstrating a security-first approach to troubleshooting sensitive meeting data.
  • [INDIRECT_PROMPT_INJECTION]: While the skill interacts with API responses, the instructions include specific guidance to verify ownership and policy if consent or access is unclear, mitigating risks associated with processing external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:43 AM
Security Audit — agent-trust-hub — fathom-common-errors