skills/vm0-ai/vm0-skills/shortio/Gen Agent Trust Hub

shortio

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl and jq to interact with the Short.io API. It employs a temporary file at /tmp/shortio_request.json for POST data, which prevents command injection by avoiding direct shell interpolation of potentially untrusted data.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the legitimate api.short.io domain. This is consistent with the skill's stated purpose of providing link shortening services via Short.io.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:15 AM