clockify-tracker
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses a secure method for handling credentials by requiring the
CLOCKIFY_API_KEYenvironment variable instead of hardcoding secrets. - [SAFE]: Network operations are directed exclusively to the official Clockify API endpoint (
api.clockify.me), which is a well-known service for time tracking. - [SAFE]: No evidence of prompt injection, obfuscation, or unauthorized command execution was found in the instructions or operational flow.
Audit Metadata