sorted-travel-visa

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to a remote Model Context Protocol (MCP) server at https://sorted.travel/mcp to provide tool functionality and data access.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses (resolve_destination and check_visa_requirements), which constitutes an attack surface for indirect prompt injection. However, the skill provides mitigation by instructing the agent to explicitly state the data source and advise users to verify information with official government sources. The skill does not possess file-writing or shell execution capabilities that could be abused by malicious data payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:21 PM
Security Audit — agent-trust-hub — sorted-travel-visa