OATDA Text Completion

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements and runtime instructions are consistent with a simple wrapper around OATDA's unified LLM API: it needs curl/jq and an OATDA API key (or the credentials file) and nothing unrelated.

This skill appears coherent: it only needs your OATDA_API_KEY (or will read it from ~/.oatda/credentials.json) and uses curl/jq to call the OATDA API. Before installing, verify you trust the OATDA service and that the homepage (https://oatda.com) is correct. Be aware that whoever has the API key can make requests that may incur charges and see prompts/responses — do not provide highly sensitive secrets to prompts. The skill's SKILL.md explicitly avoids printing the full key, which is good. If you prefer stricter control, keep the skill user-invocable (not always enabled) and consider using a key with limited scope or billing limits. If you see unexpected requests to other endpoints or extra environment variables later, revoke the API key and investigate.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.