NYC

api-rate-limiting

Fail

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: HIGH
Full Analysis
  • [SAFE]: No malicious patterns, prompt injections, or data exfiltration attempts were detected in the skill instructions or code snippets. All code follows established best practices for rate limiting logic.
  • [EXTERNAL_DOWNLOADS] (LOW): References standard, reputable libraries such as express, redis, flask, and flask-limiter. These are well-known packages used for the skill's stated purpose of implementing API protection.
  • [INFO]: The automated scanner alert for 'this.ca' is identified as a false positive, likely triggered by a substring match within the JavaScript variable name this.capacity used in the TokenBucket implementation.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 15, 2026, 10:14 PM