trmnl
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's code and instructions are consistent with its stated purpose of generating HTML content for TRMNL e-ink displays. No indicators of prompt injection, obfuscation, or unauthorized data access were found.- [COMMAND_EXECUTION]: The skill performs expected shell operations, including executing the local
scripts/check_payload.pyscript to verify payload sizes and usingcurlto transmit data to the webhook. These actions are transparently documented in the setup instructions.- [EXTERNAL_DOWNLOADS]: The skill interacts with thetrmnl.comdomain to send display updates. This is the official service for TRMNL devices and is documented as the intended destination for the generated content.- [DATA_EXFILTRATION]: While the skill transmits data externally, it does so using a webhook URL provided by the user or an environment variable. It does not attempt to access or exfiltrate sensitive system files or credentials.
Audit Metadata