clerk-testing

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and demonstration repositories hosted on clerk.com and GitHub. These references are to well-known service infrastructure belonging to the identified author (Clerk) and are used for their intended instructional purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses the WebFetch tool to ingest external documentation content. This represents a standard surface for indirect prompt injection common to documentation agents. However, the ingestion points are restricted to well-known service documentation and the functionality is central to the skill's purpose.
  • [SAFE]: The skill follows security best practices by explicitly instructing the use of test API keys (pk_test_, sk_test_) and warning against the use of production credentials in testing environments. No malicious command execution or obfuscation was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-testing