last30days
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's operations are transparent and align perfectly with its stated purpose of researching recent topics on social media. No malicious patterns, such as obfuscation, persistence, or privilege escalation, were detected.
- [COMMAND_EXECUTION]: The skill utilizes local Python scripts provided in the skill package to orchestrate its research tasks. These scripts are executed with the user's arguments and are designed to perform network requests and data processing using only Python's standard library, avoiding unverifiable third-party dependencies.
- [EXTERNAL_DOWNLOADS]: The skill connects to official endpoints for Reddit, OpenAI, and xAI. These are well-known services and the network activity is confined to retrieving relevant research data as intended. These connections do not involve downloading or executing untrusted code.
- [PROMPT_INJECTION]: The skill ingests untrusted data from social media platforms. It addresses the risk of indirect prompt injection by using intermediate scripts to normalize, truncate, and score the data before it is presented to the agent. This separation of data fetching from the main reasoning context significantly reduces the impact of potentially malicious content embedded in social media posts.
- [CREDENTIALS_SAFE]: The skill implements a secure approach for handling API keys by instructing the user to create a configuration file at
~/.config/last30days/.envwith restricted file permissions (chmod 600). This follows industry best practices for secret management and avoids the risk of hardcoded credentials.
Audit Metadata