fathom-local-dev-loop
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill is focused on setting up a local development environment for testing API integrations using synthetic data.
- [DATA_EXPOSURE]: The skill mentions the use of
.env.localfor project structure, which is a standard security best practice for managing environment-specific secrets locally and avoiding hardcoded credentials. - [INDIRECT_PROMPT_INJECTION]: While the skill involves processing meeting transcripts (a surface for untrusted data), it explicitly instructs the use of mock/synthetic data for testing and includes safety procedures for handling accidental real data exposure, reducing the risk of indirect injection during the development cycle.
- [EXTERNAL_DOWNLOADS]: The skill provides a link to
developers.fathom.aifor API documentation, which is a well-known service domain for the Fathom platform.
Audit Metadata