clerk-testing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and demonstration repositories hosted on clerk.com and GitHub. These references are to well-known service infrastructure belonging to the identified author (Clerk) and are used for their intended instructional purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill uses the WebFetch tool to ingest external documentation content. This represents a standard surface for indirect prompt injection common to documentation agents. However, the ingestion points are restricted to well-known service documentation and the functionality is central to the skill's purpose.
- [SAFE]: The skill follows security best practices by explicitly instructing the use of test API keys (pk_test_, sk_test_) and warning against the use of production credentials in testing environments. No malicious command execution or obfuscation was found.
Audit Metadata