mocreo-smart-system

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the run_shell_command tool to execute localized Python scripts within the scripts/ directory. These scripts are used to perform legitimate API interactions, such as resolving authentication, listing devices, and fetching historical sensor data.
  • [DATA_EXFILTRATION]: While the skill manages sensitive user credentials and API keys, it transmits this data exclusively to the verified vendor domain api.mocreo.com. This behavior is essential for the skill's functionality and aligns with the provided vendor context, posing no unauthorized risk.
  • [SAFE]: No malicious patterns, such as prompt injection, obfuscation, or unauthorized remote code execution, were detected. The skill includes robust helper scripts for unit normalization and timestamp formatting, which helps prevent data misinterpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 09:59 AM