nyc-dob-permits
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches property data from official NYC Open Data API endpoints at
data.cityofnewyork.usand references the author's GitHub repositoryAlpacaLabsLLC/skills-for-architects. These are well-known or author-controlled sources.- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes data from external API endpoints. - Ingestion points:
WebFetchcalls to Socrata APIs inSKILL.md. - Boundary markers: Absent.
- Capability inventory:
Bash,Write,Read, andWebFetchtools as defined in the skill frontmatter. - Sanitization: Not specified.- [SAFE]: No malicious code, obfuscation, or unauthorized access to sensitive files or credentials was detected. The skill's operations are consistent with its described functionality for building history lookups.
Audit Metadata