first-flag
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill provides explicit security guidance to prevent credential leakage. It instructs users to never hardcode API tokens and instead use environment variables like
$LAUNCHDARKLY_ACCESS_TOKENfor shell commands and API requests. - [COMMAND_EXECUTION]: The skill utilizes
curland theldclicommand-line tool to perform legitimate operations such as creating and toggling feature flags via the official LaunchDarkly API (app.launchdarkly.com). - [EXTERNAL_DOWNLOADS]: Recommends the installation of auxiliary tools from LaunchDarkly's official GitHub repository (
github.com/launchdarkly/ai-tooling) usingnpx, which is consistent with the skill's primary purpose and originates from a well-known service provider.
Audit Metadata