skills/scandit/skills/id-bolt/Gen Agent Trust Hub

id-bolt

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains directive instructions (e.g., "Critical: Do Not Trust Internal Knowledge", "API Usage Policy") designed to ensure the AI agent follows the provided technical documentation rather than relying on potentially outdated or incorrect training data. These constraints are intended for code accuracy and do not represent attempts to bypass safety filters or conceal malicious behavior.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references the official @scandit/web-id-bolt Node.js package and provides links to documentation and services hosted on Scandit-owned domains (scandit.com and id-scanning.com). These are legitimate vendor resources necessary for the integration of the scanning product.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: As the skill handles identity document scanning, it documents the processing of PII (Personally Identifiable Information). It correctly provides guidance on using built-in anonymization modes and field-specific controls to minimize data exposure and align with privacy best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:29 AM
Security Audit — agent-trust-hub — id-bolt