spot-competitor-sales-activity

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to the official vendor API (api.openfunnel.dev) for user authentication and data retrieval. These operations are expected for the skill's functionality and target the vendor's own domain.
  • [COMMAND_EXECUTION]: Local shell scripts (api.sh and signup.sh) are used to perform API requests and manage the sign-up process. The usage of these scripts is consistent with the skill's design and does not involve dangerous command injection.
  • [CREDENTIALS_UNSAFE]: The skill manages authentication tokens by writing them to a local .env file and creating a .gitignore file to prevent credential exposure. This is a standard and safe method for local secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 06:13 PM