first-flag

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides explicit security guidance to prevent credential leakage. It instructs users to never hardcode API tokens and instead use environment variables like $LAUNCHDARKLY_ACCESS_TOKEN for shell commands and API requests.
  • [COMMAND_EXECUTION]: The skill utilizes curl and the ldcli command-line tool to perform legitimate operations such as creating and toggling feature flags via the official LaunchDarkly API (app.launchdarkly.com).
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of auxiliary tools from LaunchDarkly's official GitHub repository (github.com/launchdarkly/ai-tooling) using npx, which is consistent with the skill's primary purpose and originates from a well-known service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 12:56 AM
Security Audit — agent-trust-hub — first-flag