saudi-tourism

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl to interact with official Saudi tourism API endpoints (api.visitsaudi.com). This is standard behavior for the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: Data is fetched from well-known official domains including visitsaudi.com and tdf.gov.sa. These are recognized services for regional tourism data and do not pose a risk.
  • [SAFE]: Credential management follows best practices. The skill uses environment variables (VISITSAUDI_API_KEY) for API authentication instead of hardcoding secrets.
  • [SAFE]: No evidence of prompt injection, obfuscation, persistence mechanisms, or malicious command execution was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 07:16 AM
Security Audit — agent-trust-hub — saudi-tourism