bluemind-ghost-notifications

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl to interact with the BlueMind REST API for various diagnostic steps, such as resolving user UIDs and searching for calendar events. All commands use placeholders for instance URLs and credentials, ensuring that the execution environment remains dynamic and user-controlled.
  • [EXTERNAL_DOWNLOADS]: Fetches event data in JSON format and calendar files in ICS format from the BlueMind instance. These downloads are necessary for the primary function of identifying the root cause of 'ghost' notifications.
  • [DATA_EXFILTRATION]: While the skill handles sensitive items like API keys and calendar details, it includes explicit warnings ('Ne jamais faire apparaître la clé API dans le rapport') to prevent accidental leakage of credentials in the generated output or reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 07:20 PM
Security Audit — agent-trust-hub — bluemind-ghost-notifications