perplexity-prod-checklist

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a production readiness checklist for developers. It includes security best practices such as storing API keys in secret managers rather than environment files and sanitizing queries to strip PII before sending data to external APIs.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No sensitive data or hardcoded credentials were found. The skill mentions a placeholder prefix 'pplx-' as a validation check and points to the official 'https://api.perplexity.ai' endpoint.
  • [COMMAND_EXECUTION]: While the skill lists 'Bash(kubectl:)' and 'Bash(curl:)' in its allowed-tools, the content itself does not contain any shell commands or scripts that would execute malicious actions. The tools are scoped to the deployment use-case.
  • [PROMPT_INJECTION]: The skill does not contain any instructions that attempt to override agent behavior or bypass safety filters.
  • [REMOTE_CODE_EXECUTION]: There are no patterns of downloading or executing remote scripts. The TypeScript snippets provided are illustrative code for integration and do not involve dynamic execution of untrusted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 09:39 PM
Security Audit — agent-trust-hub — perplexity-prod-checklist