llm4s-scala

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate technical resource for Scala developers. No malicious code or behaviors were detected.
  • [CREDENTIALS_UNSAFE]: The code correctly uses environment variables to manage sensitive API keys, adhering to security best practices.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, reputable libraries (ZIO, Cats Effect, FS2) as dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses string interpolation in its prompt examples. While this is an attack surface, it is a standard implementation pattern in this context.
  • Ingestion points: String interpolation in Prompt.render and LLMIO.ask in skill.md.
  • Boundary markers: None demonstrated.
  • Capability inventory: The OpenAIClient performs network calls.
  • Sanitization: None provided in the examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — llm4s-scala