agent-ready
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's official API at
ora.aito fetch readiness scores and initiate domain scans. These network operations are clearly documented and are fundamental to the skill's purpose as an agent-readiness build-time companion. - [COMMAND_EXECUTION]: Includes a utility bash script (
scripts/verify-with-ora.sh) that usescurlto interact with the Ora API. The script follows best practices, including input validation to ensure the provided domain follows standard hostname patterns and safe handling of temporary files. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Ora API, such as fix recommendations and scan details. While this represents a data ingestion surface, the risk is mitigated as the source is the vendor's own verified API, and the skill does not grant the agent high-privilege capabilities that could be exploited via these inputs.
Audit Metadata