event-discovery
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behavior or obfuscated code was identified during the audit.\n- [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface from DOME API data.\n
- Ingestion points: Fetched JSON data in
scripts/eventDiscovery.js.\n - Boundary markers: None explicitly used in prompts.\n
- Capability inventory: Limited to network operations via standard
fetch.\n - Sanitization: Employs
scripts/security.jsto strip known injection patterns and normalize whitespace in user-generated strings.\n- [EXTERNAL_DOWNLOADS]: Communicates with the officialapi.domeapi.ioendpoint, which is the legitimate and intended data source for the skill's functionality.
Audit Metadata