socai-model-sync
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches model metadata from well-known LLM provider APIs including Anthropic, OpenAI, Moonshot (Kimi), DashScope (Qwen), and DeepSeek to update the application's model catalog.
- [COMMAND_EXECUTION]: The instructions involve executing local maintenance scripts (
scripts/sync-model-catalog.mjs) and standard project tools (pnpm,cargo) to update and validate the generated catalog file. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external APIs to generate a catalog.
- Ingestion points: Official model APIs for Anthropic, OpenAI, Kimi, Qwen, and DeepSeek.
- Boundary markers: None explicitly defined for the JSON generation process.
- Capability inventory: Local script execution (
node), file write access tocore/src/agent/model_catalog.generated.json, and project build commands (pnpm,cargo). - Sanitization: The instructions explicitly advise filtering out non-agent models (e.g., embeddings, image) and normalizing model IDs to ensure compatibility with the backend.
Audit Metadata