anachb

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The shell scripts search.sh, departures.sh, and route.sh construct JSON request bodies by directly interpolating user-provided arguments into the payload. This lack of validation or escaping creates a JSON injection surface where special characters in the input could be used to manipulate the API request parameters.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to https://vao.demo.hafas.de/gate using curl to fetch transport information. This is expected behavior for the service described and targets a known transport API.
  • [SAFE]: No evidence of hardcoded credentials, persistence mechanisms, or unauthorized file system operations was found in the skill's code.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:19 PM
Security Audit — agent-trust-hub — anachb