self-xyz
Pass
Audited by Gen Agent Trust Hub on Feb 14, 2026
Risk Level: LOWEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- SAFE (SAFE): The skill contains legitimate developer documentation for identity verification. No malicious patterns such as obfuscation, credential theft, or prompt injection were found. Identity attributes are handled via zero-knowledge proofs, which is a security best practice for privacy.\n- EXTERNAL_DOWNLOADS (LOW): The skill references the installation of @selfxyz/qrcode and @selfxyz/core packages via npm. These are standard libraries required for the protocol's functionality and do not originate from suspicious sources.\n- COMMAND_EXECUTION (INFO): Standard CLI instructions for package installation and local development (ngrok) are included. These are expected for a developer integration guide and do not pose a threat.\n- INDIRECT_PROMPT_INJECTION (LOW): The skill involves processing external data (identity proofs). However, the protocol's architecture uses cryptographic proofs as a boundary, and the verification library handles sanitization. The risk of injection affecting the agent's logic is negligible.
Audit Metadata