agent-card
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'agent-cards' CLI tool from the public npm registry and connects to a remote MCP server hosted at 'https://mcp.agentcard.sh/mcp'. These resources are associated with the vendor's official infrastructure.
- [COMMAND_EXECUTION]: Instructions provide several CLI-based setup steps, including device-based OAuth login and the retrieval of local configuration tokens ('~/.agent-cards/config.json') for manual desktop configuration.
- [DATA_EXFILTRATION]: While the skill processes sensitive financial data, such as virtual card numbers and transaction history, it does so through designated MCP tools. Safety instructions explicitly prohibit the agent from displaying full card details (PAN/CVV) unless specifically requested by the user and require human confirmation for all financial transactions.
- [SAFE]: The skill implements significant safety rules, including explicit confirmation steps for closing cards, withdrawing funds, or placing orders, which mitigates the risk of autonomous financial harm.
Audit Metadata