dby-gateway

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill implements safe security practices by directing users to store API keys in environment variables and explicitly forbidding the agent from echoing or logging the credentials. It correctly uses placeholders in documentation to avoid exposing actual secrets.
  • [INDIRECT_PROMPT_INJECTION]: Analysis confirms the inclusion of proactive defensive instructions that mandate treating all data retrieved from the API as non-executable content. This approach effectively mitigates potential injection attacks that could originate from untrusted content on external platforms.
  • [EXTERNAL_DOWNLOADS]: Network activity and data fetching are directed exclusively to the platform's official domain for the purpose of retrieving configuration, input contracts, and executing authorized API calls.
  • [COMMAND_EXECUTION]: Example shell commands provided in the documentation are for manual developer use to verify index consistency and do not involve the automated execution of untrusted input by the agent at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 03:04 PM
Security Audit — agent-trust-hub — dby-gateway