skills/tiun-app/skills/tiun-sdk/Gen Agent Trust Hub

tiun-sdk

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent on how to install the official @tiun/sdk package from the NPM registry. This is a standard dependency required for the integration and is provided by the vendor.
  • [REMOTE_CODE_EXECUTION]: The documentation includes a command for installing additional agent skills using npx skills add tiun-app/skills. This process executes code from the author's official repository to extend agent functionality, which is a supported and intended feature of the platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an integration path for a Model Context Protocol (MCP) server at mcp.tiun.business. This server provides the agent with dynamic access to the user's product and provider information. While ingesting external data creates an attack surface for indirect prompt injection, the data retrieved is limited to the user's own account configuration for code generation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:49 PM
Security Audit — agent-trust-hub — tiun-sdk