nyc-dob-permits

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches property data from official NYC Open Data API endpoints at data.cityofnewyork.us and references the author's GitHub repository AlpacaLabsLLC/skills-for-architects. These are well-known or author-controlled sources.- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes data from external API endpoints.
  • Ingestion points: WebFetch calls to Socrata APIs in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Bash, Write, Read, and WebFetch tools as defined in the skill frontmatter.
  • Sanitization: Not specified.- [SAFE]: No malicious code, obfuscation, or unauthorized access to sensitive files or credentials was detected. The skill's operations are consistent with its described functionality for building history lookups.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 12:41 PM
Security Audit — agent-trust-hub — nyc-dob-permits