igrantio-credential-schema-pid-v2
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a structural reference for credential schemas. It defines metadata and JSON objects for claim paths (e.g., family_name, birthdate, resident_address) required for identity attestation.
- [EXTERNAL_DOWNLOADS]: The skill references external resources from the 'decentralised-dataexchange' repository on GitHub. These links are used to fetch the source of truth for the verifiable data registry schemas (e.g., dc+sd-jwt.schema.json). These are documented neutrally as they are central to the skill's purpose as a schema provider.
- [COMMAND_EXECUTION]: While the documentation describes how to use the iGrant.io API (e.g., POST /v2/config/digital-wallet/openid/sdjwt/credential-definition), the skill itself does not contain executable code, subprocess calls, or shell commands.
- [DATA_EXFILTRATION]: No sensitive data exposure or exfiltration patterns were found. The mention of PII fields (names, addresses, document numbers) is strictly within the context of defining a JSON schema for a verifiable credential and does not involve the collection or transmission of user data.
- [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety filters were detected in the instructions or metadata.
Audit Metadata