saudi-tourism
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlto interact with official Saudi tourism API endpoints (api.visitsaudi.com). This is standard behavior for the skill's stated purpose. - [EXTERNAL_DOWNLOADS]: Data is fetched from well-known official domains including
visitsaudi.comandtdf.gov.sa. These are recognized services for regional tourism data and do not pose a risk. - [SAFE]: Credential management follows best practices. The skill uses environment variables (
VISITSAUDI_API_KEY) for API authentication instead of hardcoding secrets. - [SAFE]: No evidence of prompt injection, obfuscation, persistence mechanisms, or malicious command execution was found.
Audit Metadata