gif-search
Fail
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill contains a hardcoded API key fragment ('AIzaSyA...') as a default value in a search command for the Tenor API.
- [COMMAND_EXECUTION]: Uses shell commands involving 'curl' and 'jq' to interact with remote APIs and process the resulting JSON data.
- [EXTERNAL_DOWNLOADS]: Fetches media files from Tenor's official Google API and Giphy's API based on search results and saves them to the local '/tmp/' directory.
Recommendations
- AI detected serious security threats
Audit Metadata