shortio
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlandjqto interact with the Short.io API. It employs a temporary file at/tmp/shortio_request.jsonfor POST data, which prevents command injection by avoiding direct shell interpolation of potentially untrusted data. - [EXTERNAL_DOWNLOADS]: The skill interacts with the legitimate
api.short.iodomain. This is consistent with the skill's stated purpose of providing link shortening services via Short.io.
Audit Metadata