trustless-work-dev

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a legitimate developer resource for integrating Trustless Work's escrow platform. All referenced external resources, including GitHub repositories (github.com/Trustless-Work/), NPM packages (@trustless-work/), and API endpoints (api.trustlesswork.com), belong to the verified vendor or are well-known industry services.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The documentation correctly advises users to manage API keys via environment variables and warns against exposing them in client-side code. Hardcoded keys are not present; only placeholders for user configuration are used.
  • [REMOTE_CODE_EXECUTION]: Installation and initialization steps use standard package managers and vendor-specific CLI tools (npx skills add, npx trustless-work init). These are standard for development workflows and originate from the vendor's controlled infrastructure.
  • [PROMPT_INJECTION]: The instructions provided to the agent focus on maintaining code quality and following vendor-specific implementation patterns. There are no attempts to bypass safety filters or override system-level instructions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill assists the agent in processing user-supplied data for code generation (e.g., creating escrow payloads), the associated risks are minimized by the agent's typical operational guardrails and the clear documentation of expected data types and schemas (LOW severity finding).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 12:06 AM
Security Audit — agent-trust-hub — trustless-work-dev