agent-card
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill follows security best practices by implementing explicit user confirmation steps for financial operations.\n- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the official agent-cards CLI tool via npm and connects to the vendor's MCP server (mcp.agentcard.sh). These are recognized vendor resources and do not pose an external download risk.\n- [COMMAND_EXECUTION]: Procedural instructions guide the agent and user through the setup and operation of the AgentCard CLI. These commands are restricted to the intended functionality of the skill.\n- [CREDENTIALS_UNSAFE]: The documentation describes how users can manually retrieve a JWT token from their local configuration file (~/.agent-cards/config.json) for the purpose of setting up desktop integrations. This is a legitimate configuration step and not an automated credential harvest.
Audit Metadata