malloy-getting-started

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions include commands to download and run packages from the @malloy-publisher scope on the npm registry using npx and npm create. These resources are official components of the Malloy Publisher ecosystem designed for project scaffolding and server execution.
  • [COMMAND_EXECUTION]: The skill describes how to start a local server using npx or bun and how to scaffold new projects. These commands are intended for local development environments and are standard for the described workflow.
  • [DATA_EXFILTRATION]: Network activity is restricted to local status checks (localhost:4000) and the official npm registry for package installation. No unauthorized transmission of sensitive data to external or untrusted domains was detected.
  • [PROMPT_INJECTION]: The instructions emphasize 'grounded discovery' and explicitly forbid the agent from guessing names or inventing environments. It provides a structured workflow to ensure actions are based on verifiable metadata returned by the tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:02 AM
Security Audit — agent-trust-hub — malloy-getting-started