aura-asset-images
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches assets from the official aura.build website and its backend storage at hoirqrkdgbmvpwutwuwj.supabase.co, which is a well-known service infrastructure.
- [PROMPT_INJECTION]: The skill instructs the agent to search external web content from aura.build using WebFetch, which constitutes a vulnerability surface for indirect prompt injection. 1. Ingestion points: The skill uses WebFetch to retrieve data from aura.build (SKILL.md). 2. Boundary markers: Absent; no delimiters are defined for processing external data. 3. Capability inventory: Bash, Read, Write, Edit, Glob, Grep. 4. Sanitization: Absent.
Audit Metadata