next-bulk-move

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves a legitimate purpose for managing e-commerce fulfillment orders. Its instructions are clear, transparent, and do not contain any malicious directives.
  • [COMMAND_EXECUTION]: The skill provides Python code snippets for reading local data files using the pandas library and executing API requests. These commands are used to automate the move workflow and are confined to the user's local environment and the target platform.
  • [CREDENTIALS_UNSAFE]: The skill handles authentication by requesting an Admin API access token from the user through a guided setup process. It instructs the agent to use the token in HTTP headers, following standard security practices for secret management.
  • [DATA_EXFILTRATION]: All network activity is directed to the official 29next.store API. The skill does not attempt to send sensitive information, such as API keys or order data, to unauthorized external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 10:23 AM
Security Audit — agent-trust-hub — next-bulk-move