upstash-box-js
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and API examples for the @upstash/box SDK, a legitimate service for managing sandboxed environments.
- [SAFE]: The documentation includes security best practices, such as using network policies to restrict outbound access when dealing with untrusted code or repositories.
- [SAFE]: While the skill contains examples for running shell commands and code, this is the primary intended functionality of the sandbox service and is executed within an isolated container.
- [SAFE]: API key examples (e.g., sk-, GITHUB_TOKEN) are used as placeholders within standard SDK configuration patterns and do not represent leaked credentials.
Audit Metadata