skills/viralcode/openwhale/trmnl/Gen Agent Trust Hub

trmnl

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's code and instructions are consistent with its stated purpose of generating HTML content for TRMNL e-ink displays. No indicators of prompt injection, obfuscation, or unauthorized data access were found.- [COMMAND_EXECUTION]: The skill performs expected shell operations, including executing the local scripts/check_payload.py script to verify payload sizes and using curl to transmit data to the webhook. These actions are transparently documented in the setup instructions.- [EXTERNAL_DOWNLOADS]: The skill interacts with the trmnl.com domain to send display updates. This is the official service for TRMNL devices and is documented as the intended destination for the generated content.- [DATA_EXFILTRATION]: While the skill transmits data externally, it does so using a webhook URL provided by the user or an environment variable. It does not attempt to access or exfiltrate sensitive system files or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 12:14 AM
Security Audit — agent-trust-hub — trmnl