airweave-setup

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the installation of official libraries (airweave-sdk and @airweave/sdk) from public registries and the cloning of the vendor's repository from GitHub. These resources are from established, vendor-specific paths and are necessary for the skill's documented purpose.
  • [COMMAND_EXECUTION]: Contains standard commands for development environments, such as package installation and starting a local server via shell scripts. These actions are transparently documented as part of the setup workflow.
  • [DATA_EXPOSURE]: Documentation describes how to configure API keys for external services. It uses clear placeholders and explicitly recommends using environment variables for sensitive configuration, aligning with security best practices.
  • [INDIRECT_PROMPT_INJECTION]: As a retrieval-augmented generation (RAG) tool, it establishes a surface for processing data from connected third-party sources.
  • Ingestion points: Data ingested from 40+ connected productivity, communication, and development tools.
  • Boundary markers: Not present in the instructional prompt examples.
  • Capability inventory: Provides a search tool allowing agents to query and retrieve information from connected collections.
  • Sanitization: Not documented; behavior relies on the underlying platform's handling of retrieved content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 03:34 AM