hotapi
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [DATA_EXPOSURE]: The skill includes explicit instructions to protect sensitive credentials, specifically the
HOTAPI_KEY. It directs the user to keep the key in trusted server-side code and prevents exposure in logs, commits, or transcripts. - [INDIRECT_PROMPT_INJECTION]: The skill identifies external sources of truth (OpenAPI schemas and documentation at hotapi.ai) for the agent to process. While this creates an ingestion point for external data, it is a standard practice for API integration skills and does not include dangerous capabilities or automated execution.
- [NO_CODE]: The skill contains no executable scripts, dependencies, or automated command-line operations, significantly reducing its attack surface.
Audit Metadata