lovebug-report

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with public, unauthenticated APIs on the xn--2i0bt2q2wd1wb.com (lovebug.com) domain and a public Supabase instance. These are legitimate public surfaces for the intended local information reporting service.- [SAFE]: The instructions explicitly prohibit executing submissions without user approval and forbid storing or printing plaintext credentials. This aligns with security best practices for AI agents.- [EXTERNAL_DOWNLOADS]: The skill uses npx to run instructions and list files from @nomadamas/k-skill. These resources belong to the vendor 'NomaDamas', the same author as the skill. This represents standard operational behavior for this vendor's ecosystem and does not pose a security risk. All referenced GitHub URLs and NPM packages are consistent with the vendor's verified naming patterns.- [DATA_EXFILTRATION]: No evidence of unauthorized data exfiltration was found. Network requests are limited to the primary service provider (lovebug.com) and the associated Supabase RPC endpoint for the express purpose of fetching and submitting local pest data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 06:47 AM
Security Audit — agent-trust-hub — lovebug-report