yaak-cli
Pass
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
yaakCLI andjqutility to inspect and manage local API development workspaces. These operations are within the scope of the skill's documented purpose. - [DATA_EXFILTRATION]: While the skill's primary function is to send API requests, it incorporates specific safety constraints to prevent data leakage, such as prohibiting verbose mode and requiring the removal of authentication fields from command outputs before they are processed by the agent.
- [SAFE]: The skill demonstrates security awareness by providing clear guidelines on how to handle sensitive authentication data and avoiding the exposure of inherited bearer tokens.
Audit Metadata