mistral
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill provides instructions for configuring Mistral API keys using CLI commands (
initor--cfg apikey=<key>). This represents standard API key configuration management and no hardcoded credentials were observed. \n- [COMMAND_EXECUTION]: The skill instructions involve the use ofx mistraland@mistral, which are tools provided by the vendor (x-cmd). Their use is aligned with the skill's documented functionality. \n- [PROMPT_INJECTION]: The skill facilitates the processing of external data via the--fileparameter, which is a surface for indirect prompt injection. \n - Ingestion points: File content read via the
--fileflag inSKILL.md. \n - Boundary markers: None mentioned. \n
- Capability inventory: Shell command execution using
x mistralto interact with Mistral AI APIs. \n - Sanitization: No sanitization or validation of the file content is described.
Audit Metadata