static-egress
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes management and utility scripts (enable.py, disable.py, status.py, verify.py, tunnel.py) that allow the agent to configure and route network traffic via a relay service. These tools are functional and restricted to their documented purpose.
- [EXTERNAL_DOWNLOADS]: The
selftest.pyscript performs network requests to well-known services (ifconfig.co and example.com) to verify that outbound IP addresses are correctly reported and that TLS hostname verification is preserved through the relay. These operations are diagnostic in nature. - [DYNAMIC_EXECUTION]: The
exports.pyfile dynamically loads internal programmatic interfaces using Python'simportlib. This loading is confined to local files within the skill's directory and does not involve remote code or untrusted paths. - [INDIRECT_PROMPT_INJECTION]: The skill handles target hostnames and ports provided via user input. While this provides a surface for connection attempts to external endpoints, the underlying relay service implements policy checks that refuse connections to internal, loopback, or private network ranges.
Audit Metadata