scalekit-code-doctor
Pass
Audited by Gen Agent Trust Hub on May 21, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is configured to fetch SDK reference files and documentation from official vendor sources including
raw.githubusercontent.com/scalekit-inc/anddocs.scalekit.com. These resources are maintained by the skill author and are used to ensure code correctness. - [PROMPT_INJECTION]: The 'Review mode' functionality creates a surface for indirect prompt injection as it ingests and analyzes user-provided code. However, because the skill has no access to sensitive system resources, file writing, or command execution tools, this surface does not pose a significant security risk.
- [DATA_EXPOSURE]: The skill documentation correctly identifies and warns against security anti-patterns such as hardcoded credentials and unvalidated redirects, promoting the use of environment variables and secure cookie configurations.
Audit Metadata