agent-card

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill follows security best practices by implementing explicit user confirmation steps for financial operations.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the official agent-cards CLI tool via npm and connects to the vendor's MCP server (mcp.agentcard.sh). These are recognized vendor resources and do not pose an external download risk.\n- [COMMAND_EXECUTION]: Procedural instructions guide the agent and user through the setup and operation of the AgentCard CLI. These commands are restricted to the intended functionality of the skill.\n- [CREDENTIALS_UNSAFE]: The documentation describes how users can manually retrieve a JWT token from their local configuration file (~/.agent-cards/config.json) for the purpose of setting up desktop integrations. This is a legitimate configuration step and not an automated credential harvest.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 03:46 PM
Security Audit — agent-trust-hub — agent-card