openydt-shared

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes proactive instructions that warn against treating data fields from the platform as commands, which provides defense against indirect prompt injection attacks.
  • [DATA_EXPOSURE]: Accesses and manages sensitive configuration paths such as ~/.config/openydt-cli/config.json, but enforces restricted file permissions (0600) and secret masking to protect user credentials.
  • [DATA_EXFILTRATION]: Network operations are directed exclusively to official service domains (yidianting.com.cn, yidianting.xin) for intended API functions, with no unauthorized data transmission detected.
  • [EXTERNAL_DOWNLOADS]: Documents a standard tool update command (openydt update) used to maintain the CLI and its associated business skills through official package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:22 PM
Security Audit — agent-trust-hub — openydt-shared