a1-yandex-kit-store

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for managing e-commerce resources via the Yandex KIT REST API. All included logic is transparent and follows standard development practices.
  • [COMMAND_EXECUTION]: The provided script search_docs.mjs uses standard Node.js built-in modules to parse a local, bundled OpenAPI specification. It avoids unsafe execution patterns, network operations, and external dependencies.
  • [CREDENTIALS_SAFE]: The skill correctly instructs the user to provide authentication tokens via environment variables (YANDEX_KIT_TOKEN) rather than hardcoding credentials.
  • [DATA_EXPOSURE]: No evidence was found of scripts or instructions attempting to access sensitive local files or exfiltrate environment data to unauthorized endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 03:15 PM
Security Audit — agent-trust-hub — a1-yandex-kit-store