sn-search-code

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with several well-known developer platform APIs to perform searches.
  • Interacts with GitHub's REST API at api.github.com for repository, code, and issue searches.
  • Interacts with the Hacker News Algolia API at hn.algolia.com for community discussions.
  • Interacts with the HuggingFace Hub API at huggingface.co/api for models and datasets.
  • Interacts with the Stack Exchange API at api.stackexchange.com for technical Q&A.
  • [CREDENTIALS_UNSAFE]: The skill follows secure credential management practices by avoiding hardcoded secrets.
  • Documentation in SKILL.md instructs users to manage API keys via .env files or environment variables.
  • Scripts like github_search.py and huggingface_search.py read credentials from environment variables (GITHUB_TOKEN, HF_TOKEN) or optional command-line arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external search data using structured formats and basic sanitization.
  • Ingestion points: Data is ingested from the GitHub, Stack Overflow, Hacker News, and HuggingFace APIs across all search scripts.
  • Boundary markers: The skill returns data to the agent in a structured JSON format, providing clear separation between data and instructions.
  • Capability inventory: The skill is restricted to network-based data retrieval from trusted domains and does not possess capabilities for file modification or shell command execution.
  • Sanitization: The _strip_html utility in scripts/stackoverflow_search.py and scripts/hackernews_search.py removes HTML tags from external content snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-search-code