scalekit-code-doctor

Pass

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is configured to fetch SDK reference files and documentation from official vendor sources including raw.githubusercontent.com/scalekit-inc/ and docs.scalekit.com. These resources are maintained by the skill author and are used to ensure code correctness.
  • [PROMPT_INJECTION]: The 'Review mode' functionality creates a surface for indirect prompt injection as it ingests and analyzes user-provided code. However, because the skill has no access to sensitive system resources, file writing, or command execution tools, this surface does not pose a significant security risk.
  • [DATA_EXPOSURE]: The skill documentation correctly identifies and warns against security anti-patterns such as hardcoded credentials and unvalidated redirects, promoting the use of environment variables and secure cookie configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 21, 2026, 05:09 PM
Security Audit — agent-trust-hub — scalekit-code-doctor