retool-skill

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a build and automation toolkit for Retool applications. No malicious behavior was detected across any threat category.- [COMMAND_EXECUTION]: Shell scripts such as zip_app.sh and bundle-apps.sh are utilized for standard file operations and packaging. These scripts follow safe practices, including the use of set -euo pipefail and proper variable quoting to prevent word-splitting or command injection issues.- [REMOTE_CODE_EXECUTION]: All automation logic is implemented in local Python scripts that rely exclusively on the Python standard library. No remote scripts are downloaded or executed, and there is no dependency on external package registries.- [DATA_EXFILTRATION]: No network activity or credential harvesting logic was identified. The RESTQuery examples provided in the asset templates use placeholder domains and are intended for user-directed development reference.- [PROMPT_INJECTION]: The skill definition and instructions contain no attempts to override AI safety guardrails or bypass system constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 12:18 PM
Security Audit — agent-trust-hub — retool-skill