nutmeg-acquire

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for managing API keys and secrets. It correctly recommends using .env files and environment variables, and emphasizes the importance of using .gitignore to prevent credential leakage. It uses appropriate placeholders for provider-specific keys (e.g., SPORTMONKS_API_TOKEN, WYSCOUT_API_KEY).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from various external sources including web scraping (FBref, Understat) and REST APIs (StatsBomb, SportMonks).
  • Ingestion points: External API responses, web scraping results, and local user configuration files (.nutmeg.user.md).
  • Boundary markers: None explicitly defined in prompt templates, but the instructions include a 'Security' section warning the agent to treat external content as untrusted.
  • Capability inventory: The skill has access to Bash, Write, Read, and Agent tools.
  • Sanitization: The skill instructs the agent to validate data shapes, check for sensible row/event counts, and verify expected schemas before processing external data.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data and code snippets from well-known football data services (StatsBomb, Opta, SportMonks) and the author's official GitHub repository (withqwerty/reep). These references represent standard functionality for the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:24 PM
Security Audit — agent-trust-hub — nutmeg-acquire