socai-model-sync

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches model metadata from well-known LLM provider APIs including Anthropic, OpenAI, Moonshot (Kimi), DashScope (Qwen), and DeepSeek to update the application's model catalog.
  • [COMMAND_EXECUTION]: The instructions involve executing local maintenance scripts (scripts/sync-model-catalog.mjs) and standard project tools (pnpm, cargo) to update and validate the generated catalog file.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external APIs to generate a catalog.
  • Ingestion points: Official model APIs for Anthropic, OpenAI, Kimi, Qwen, and DeepSeek.
  • Boundary markers: None explicitly defined for the JSON generation process.
  • Capability inventory: Local script execution (node), file write access to core/src/agent/model_catalog.generated.json, and project build commands (pnpm, cargo).
  • Sanitization: The instructions explicitly advise filtering out non-agent models (e.g., embeddings, image) and normalizing model IDs to ensure compatibility with the backend.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:24 AM
Security Audit — agent-trust-hub — socai-model-sync