clay-reference-architecture

Fail

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE] (SAFE): No malicious prompt injection, data exfiltration, or persistence mechanisms were detected.- [EXTERNAL_DOWNLOADS] (SAFE): The automated security alert for 'this.ca' is a false positive. The string is part of the code snippet this.cache in the src/clay/client.ts section and does not represent a malicious network connection.- [COMMAND_EXECUTION] (LOW): The skill includes a shell script example in the documentation for creating a local directory structure (mkdir -p). This is a standard developer utility and poses no security risk.- [CREDENTIALS_UNSAFE] (SAFE): No hardcoded API keys or secrets were found. The configuration management section uses placeholders like apiKey: string and refers to environment variables.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 18, 2026, 09:33 PM