Not yet reviewed
This listing hasn’t completed an AgentStack security review yet. Listings earn the green verified badge only after a version passes automated scanning for prompt injection, secret exfiltration, and dangerous tool calls.
Read about how the review process works →
What this report covers
- Prompt injection — instructions hidden in tool descriptions or outputs that try to hijack the agent.
- Secret exfiltration — code paths that read credentials or environment and send them off-box.
- Dangerous tool calls — unguarded shell, filesystem, or network access.
Automated scanning runs on every published version before it can list publicly. Full methodology →
Embed this badge
Add the verification badge to your GitHub README — it links back to this report.