skills/vm0-ai/vm0-skills/sproutgigs/Gen Agent Trust Hub

sproutgigs

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl to interact with the SproutGigs API. These commands are static, follow official API documentation, and target the official domain sproutgigs.com.- [CREDENTIALS_UNSAFE]: The skill correctly uses environment variables (SPROUTGIGS_USER_ID, SPROUTGIGS_API_SECRET) for authentication. No hardcoded credentials or secrets were found. Instruction to use .env files for secret management is consistent with security best practices.- [EXTERNAL_DOWNLOADS]: No external scripts, packages, or binary dependencies are downloaded or executed. All logic is contained within the provided markdown and shell helpers.- [PROMPT_INJECTION]: No attempts to override system prompts or bypass safety guidelines were detected. The instructions focus purely on operational tasks and API management.- [DATA_EXFILTRATION]: Network operations are restricted to the official sproutgigs.com API endpoints. There is no evidence of sensitive local data being transmitted to unauthorized third-party domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:52 AM
Security Audit — agent-trust-hub — sproutgigs