flask-api-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions and code templates for building web APIs that ingest untrusted data from external sources.
- Ingestion points: API endpoints defined in
references/blueprints-for-modular-api-design.mdandreferences/authentication-and-jwt.mdaccept data via HTTP request bodies and query parameters. - Boundary markers: The templates do not include explicit instructions or markers to delimit untrusted data from agent instructions.
- Capability inventory: The code templates include database access capabilities (CRUD operations) via SQLAlchemy.
- Sanitization: The templates provide minimal sanitization (email regex and field presence checks), leaving a wide surface for processing unsanitized data.
Audit Metadata