skills/vesely/skills/ai-gateway/Gen Agent Trust Hub

ai-gateway

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @vesely/ai-gateway-cli package from the NPM registry to provide its core functionality. This package is an official resource provided by the skill author.
  • [COMMAND_EXECUTION]: The skill relies on shell commands to check for the CLI's presence (which), install it globally if missing (npm install -g), and execute generation tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts arbitrary text prompts and file content as input to be processed by external AI models, which is an inherent part of its content generation functionality.
  • Ingestion points: User-provided prompts and piped file content in commands like cat file.md | ai-gateway "<prompt>".
  • Boundary markers: None explicitly defined; the skill passes raw input to the CLI tool.
  • Capability inventory: Shell command execution and network communication via the external CLI tool.
  • Sanitization: No specific sanitization or filtering of input text is implemented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:20 PM
Security Audit — agent-trust-hub — ai-gateway