ai-coding-agents-provider-runtime

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily educational and architectural documentation. It does not include executable code or commands that present a security risk.
  • [EXTERNAL_DOWNLOADS]: The skill includes references to official documentation and open-source repositories for OpenAI, Anthropic, Gemini, and Goose. These references are used for informational purposes and design alignment with industry standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill addresses the vulnerability surface of processing external provider data by recommending strict normalization at the runtime boundary. It suggests using a stable internal event model and validating tool-call arguments, which are effective mitigations against untrusted input from LLMs.
  • [CREDENTIALS_UNSAFE]: The skill promotes secure authentication practices, such as using environment variables for API keys and browser-based OAuth, and includes explicit warnings against exposing local model servers like Ollama to public networks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-coding-agents-provider-runtime