airweave-setup
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the installation of official libraries (airweave-sdk and @airweave/sdk) from public registries and the cloning of the vendor's repository from GitHub. These resources are from established, vendor-specific paths and are necessary for the skill's documented purpose.
- [COMMAND_EXECUTION]: Contains standard commands for development environments, such as package installation and starting a local server via shell scripts. These actions are transparently documented as part of the setup workflow.
- [DATA_EXPOSURE]: Documentation describes how to configure API keys for external services. It uses clear placeholders and explicitly recommends using environment variables for sensitive configuration, aligning with security best practices.
- [INDIRECT_PROMPT_INJECTION]: As a retrieval-augmented generation (RAG) tool, it establishes a surface for processing data from connected third-party sources.
- Ingestion points: Data ingested from 40+ connected productivity, communication, and development tools.
- Boundary markers: Not present in the instructional prompt examples.
- Capability inventory: Provides a search tool allowing agents to query and retrieve information from connected collections.
- Sanitization: Not documented; behavior relies on the underlying platform's handling of retrieved content.
Audit Metadata