ev-subsidy-status

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES]: The skill runs the 'ev-subsidy-status' package via npx. This is a vendor-aligned tool used to retrieve and process government data.\n- [DYNAMIC_EXECUTION]: The skill parses protected payloads from the target website using a static character map. It explicitly avoids using 'eval' or 'vm' to execute remote JavaScript, reducing the risk of unauthorized code execution.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external HTML content. It uses strict DOM selectors to isolate specific data points. Ingestion points: government portal status tables. Boundary markers: None. Capability inventory: npx subprocess execution. Sanitization: DOM filtering and keyword mapping.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 01:47 PM
Security Audit — agent-trust-hub — ev-subsidy-status