ae-engage

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill 'ae-engage' acts as a wrapper for the 'ae-cli' utility. A thorough review of the instructions and reference materials revealed no malicious patterns, prompt injection attempts, or unauthorized data exfiltration logic.
  • [COMMAND_EXECUTION]: The core functionality of the skill involves the agent constructing and executing shell commands using the 'ae-cli' binary. These commands often include complex JSON-formatted payloads ('--req') built from user intent. This behavior is consistent with the skill's primary purpose and is governed by strict safety constraints, including a mandatory confirmation step for all write-related actions and the availability of a dry-run mode to preview requests.
  • [CREDENTIALS_UNSAFE]: The skill documents how the 'ae-cli' tool handles authentication, mentioning the use of environment variables ('TE_TOKEN') and local configuration files ('~/.ae-cli/tokens.json'). It also describes a feature of the CLI tool on macOS that can extract tokens from the Chrome browser. These descriptions are informational for the agent to understand the tool's authentication flow and do not constitute an instruction to exfiltrate or misuse credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 07:23 AM
Security Audit — agent-trust-hub — ae-engage