a1-yandex-kit-store
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for managing e-commerce resources via the Yandex KIT REST API. All included logic is transparent and follows standard development practices.
- [COMMAND_EXECUTION]: The provided script
search_docs.mjsuses standard Node.js built-in modules to parse a local, bundled OpenAPI specification. It avoids unsafe execution patterns, network operations, and external dependencies. - [CREDENTIALS_SAFE]: The skill correctly instructs the user to provide authentication tokens via environment variables (
YANDEX_KIT_TOKEN) rather than hardcoding credentials. - [DATA_EXPOSURE]: No evidence was found of scripts or instructions attempting to access sensitive local files or exfiltrate environment data to unauthorized endpoints.
Audit Metadata