skills/scandit/skills/id-bolt/Gen Agent Trust Hub

id-bolt

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a developer guide for the Scandit ID Bolt SDK, focusing on configuration, document selection, and result handling within a web environment.
  • [EXTERNAL_DOWNLOADS]: The skill references the official vendor package @scandit/web-id-bolt and links to official documentation and service endpoints under the scandit.com and id-scanning.com domains. These are trusted resources associated with the verified author.
  • [PROMPT_INJECTION]: The skill contains instructions to ensure the AI agent distinguishes between two similar products (ID Bolt vs. ID Capture) to prevent generating non-working code. These are benign instructional constraints and do not constitute an attempt to bypass safety protocols or hijack agent behavior.
  • [CREDENTIALS_UNSAFE]: Code examples utilize clear placeholders for sensitive information, such as -- YOUR LICENSE KEY HERE --, adhering to security best practices for shared documentation.
  • [DATA_EXFILTRATION]: While the skill involves processing identity document data (PII), it describes the primary intended purpose of the vendor's product. It proactively includes guidance on data anonymization and privacy features to help developers minimize the collection of sensitive data.
  • [COMMAND_EXECUTION]: No suspicious shell commands or dynamic execution patterns were identified. The included code is standard TypeScript for library integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 02:40 PM
Security Audit — agent-trust-hub — id-bolt