dot-device-openapi

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs network operations exclusively to the vendor-owned domain 'dot.mindreset.tech', which is appropriate for its intended functionality.
  • [SAFE]: Sensitive API keys are managed using the DOT_API_KEY environment variable, avoiding the risks associated with hardcoding credentials.
  • [SAFE]: The 'send_canvas.py' script implements comprehensive validation for Canvas API payloads, including nesting depth checks, element type whitelisting, and protection against unsafe object keys, which mitigates potential injection risks in the device rendering engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 03:40 AM
Security Audit — agent-trust-hub — dot-device-openapi