skills/ora/skills/agent-ready/Gen Agent Trust Hub

agent-ready

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's official API at ora.ai to fetch readiness scores and initiate domain scans. These network operations are clearly documented and are fundamental to the skill's purpose as an agent-readiness build-time companion.
  • [COMMAND_EXECUTION]: Includes a utility bash script (scripts/verify-with-ora.sh) that uses curl to interact with the Ora API. The script follows best practices, including input validation to ensure the provided domain follows standard hostname patterns and safe handling of temporary files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Ora API, such as fix recommendations and scan details. While this represents a data ingestion surface, the risk is mitigated as the source is the vendor's own verified API, and the skill does not grant the agent high-privilege capabilities that could be exploited via these inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 PM