skills/legnext-ai/hotapi-skill/hotapi/Gen Agent Trust Hub

hotapi

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [DATA_EXPOSURE]: The skill includes explicit instructions to protect sensitive credentials, specifically the HOTAPI_KEY. It directs the user to keep the key in trusted server-side code and prevents exposure in logs, commits, or transcripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies external sources of truth (OpenAPI schemas and documentation at hotapi.ai) for the agent to process. While this creates an ingestion point for external data, it is a standard practice for API integration skills and does not include dangerous capabilities or automated execution.
  • [NO_CODE]: The skill contains no executable scripts, dependencies, or automated command-line operations, significantly reducing its attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 03:43 PM
Security Audit — agent-trust-hub — hotapi