anygen-doc
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill securely manages sensitive credentials by storing the API key in a configuration file (
~/.config/anygen/config.json) with restricted filesystem permissions (chmod 600), ensuring only the owner can access it.\n- [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's official domain (www.anygen.io) and well-known technology services (open.feishu.cn). These network operations are necessary for the skill's primary purpose and do not involve untrusted or suspicious sources.\n- [SAFE]: The skill's implementation is transparent and follows secure coding standards, such as disabling HTTP redirects for all API requests to prevent redirection-based attacks.\n- [PROMPT_INJECTION]: Instructions for background monitoring and document modification are structured logically for agent orchestration and do not contain attempts to bypass safety filters or override core system instructions.\n- [SAFE]: No evidence of obfuscation, privilege escalation, or persistence mechanisms was found in the provided scripts or documentation.
Audit Metadata