managed-pentesting-with-strix

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous curl and jq examples for interacting with the Strix REST API. These are benign and follow standard documentation patterns for API integration.
  • [EXTERNAL_DOWNLOADS]: The skill references official Strix documentation (docs.app.strix.ai) and the OpenAPI specification (docs.app.strix.ai/openapi.json). These are trusted resources belonging to the skill's authoring vendor, usestrix.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs users to store their API tokens in environment variables (STRIX_API_TOKEN) or CI secret stores. It explicitly warns against hardcoding, logging, or committing tokens.
  • [SAFE]: The skill includes a dedicated 'Safety' section emphasizing that users must only scan authorized assets and that the platform enforces domain verification to prevent unauthorized testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:29 PM
Security Audit — agent-trust-hub — managed-pentesting-with-strix