write-provider-skill

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and documents a workflow for building API provider skills. It describes how to interact with a local development proxy ('treg') for testing API integrations.
  • [COMMAND_EXECUTION]: The skill provides examples of shell commands for local development using scripts/dev-local.sh and sqlite3. These commands are standard for developers testing their own local environments and do not involve remote execution or untrusted input.
  • [DATA_EXPOSURE]: The skill explicitly instructs agents not to hold credentials, stating that all calls must go through a proxy ('you never hold a credential'). It also includes a 'Write-side testing' protocol to prevent accidental modifications to production accounts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 10:50 PM
Security Audit — agent-trust-hub — write-provider-skill