mocreo-smart-system
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
run_shell_commandtool to execute localized Python scripts within thescripts/directory. These scripts are used to perform legitimate API interactions, such as resolving authentication, listing devices, and fetching historical sensor data. - [DATA_EXFILTRATION]: While the skill manages sensitive user credentials and API keys, it transmits this data exclusively to the verified vendor domain
api.mocreo.com. This behavior is essential for the skill's functionality and aligns with the provided vendor context, posing no unauthorized risk. - [SAFE]: No malicious patterns, such as prompt injection, obfuscation, or unauthorized remote code execution, were detected. The skill includes robust helper scripts for unit normalization and timestamp formatting, which helps prevent data misinterpretation.
Audit Metadata