onelogin
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes standard environment variables (
APIDECK_API_KEY,APIDECK_APP_ID) for secret management, avoiding hardcoded credentials. - [SAFE]: All external URL references and network operations (via
curland SDK examples) target official vendor domains, specificallyapideck.com,unify.apideck.com, anddevelopers.apideck.com. - [SAFE]: The skill references the official vendor library
@apideck/unifyfor implementation. - [SAFE]: No patterns of obfuscation, persistence, privilege escalation, or malicious command execution were detected.
- [LOW]: Regarding Indirect Prompt Injection, the skill processes data from external HRIS sources (OneLogin). While this constitutes an attack surface, the risk is mitigated by the use of structured API interactions and standard LLM safety protocols.
Audit Metadata