sorted-travel-destinations

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches travel destination data and safety facts from https://sorted.travel via a zero-authentication MCP server and API endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external travel catalogs and tool outputs which could contain malicious instructions. Ingestion points: resolve_destination and get_destination_info tool outputs, sitemap.xml, and destinations.jsonl feed (referenced in SKILL.md). Boundary markers: No specific delimiters or instructions to ignore embedded content are defined in SKILL.md. Capability inventory: The skill uses network-based tools to retrieve data from the sorted.travel domain as defined in SKILL.md. Sanitization: No explicit sanitization or validation of the remote content is described in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:21 PM
Security Audit — agent-trust-hub — sorted-travel-destinations