api-database-upstash

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill integrates official libraries from a well-known service provider (@upstash/redis, @upstash/ratelimit, and @upstash/qstash). All remote operations are consistent with the intended functionality of a serverless database client and task scheduler. No untrusted execution patterns were found.
  • [CREDENTIALS_UNSAFE]: The documentation adheres to high security standards by explicitly prohibiting the hardcoding of API tokens and URLs. It provides clear instructions on using Redis.fromEnv() and environment variables to manage sensitive credentials securely.
  • [DATA_EXFILTRATION]: Network activity is restricted to established Upstash service domains and user-configured application endpoints for webhook delivery. There are no patterns indicating unauthorized or suspicious data movement.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages external data through a serverless Redis interface. It leverages automatic JSON serialization, which provides a structured data boundary, and lacks any patterns that would lead an agent to interpret retrieved data as executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:56 PM
Security Audit — agent-trust-hub — api-database-upstash