getting-started

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements secure authentication practices by explicitly instructing the agent to NEVER ask the user to paste tokens into the chat. It directs users to standard OAuth flows or environment variable configuration (TTAI_PAT) for headless environments.
  • [EXTERNAL_DOWNLOADS]: The skill references the official Tough Tongue AI API and MCP server at api.toughtongueai.com. These are verified vendor resources belonging to the skill author 'tough-tongue'.
  • [COMMAND_EXECUTION]: The instructions include standard setup commands for platform-specific MCP registration (e.g., codex mcp add, claude mcp add, launchctl setenv). These are used for legitimate configuration of the environment and do not involve shell injection or dangerous execution patterns.
  • [DATA_EXPOSURE]: While the skill accesses account data such as organizations, scenarios, and sessions, it does so through the authorized vendor MCP toolset and limits access to the context of the user's own account orientation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 10:52 AM
Security Audit — agent-trust-hub — getting-started