topview-skill
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions for the agent to suppress technical details (logs, environment variables, exit codes) in its communication with users. This is explicitly documented as a UX preference for non-technical users but represents a behavioral override that simplifies reporting of internal operations.
- [EXTERNAL_DOWNLOADS]: The skill includes functionality to download generated images and videos from official Topview AI domains (*.topview.ai) to the user's local directory.
- [SAFE]: Authentication is handled via the secure OAuth 2.0 Device Flow, and credentials are stored locally with restrictive 0600 file permissions, adhering to security best practices for CLI tools.
Audit Metadata