invoke-deployment
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill strictly manages authentication by instructing the agent to never hardcode the
ORQ_API_KEYin generated code and to use environment variables instead, which prevents the accidental exposure of sensitive credentials. - [SAFE]: All network operations described in the workflow and API reference are directed towards the vendor's official domains (
api.orq.ai,docs.orq.ai,my.orq.ai). These operations are legitimate and necessary for fetching resource configurations and invoking the service. - [SAFE]: The skill provides standard integration code templates for well-known libraries and tools such as the Python SDK, Node.js SDK, and
curl, ensuring that user integrations follow established patterns without introducing suspicious execution logic. - [SAFE]: No obfuscation, persistence mechanisms, or unauthorized privilege escalation attempts were detected. The skill's behavior is consistent with its stated purpose as an integration assistant for the orq.ai platform.
Audit Metadata