nyc-landmarks

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from external APIs which could contain malicious instructions (Indirect Prompt Injection).\n
  • Ingestion points: SKILL.md fetches data from data.cityofnewyork.us/resource/64uk-42ks.json and data.cityofnewyork.us/resource/buis-pvji.json.\n
  • Boundary markers: Absent. No specific delimiters are used to wrap the external content.\n
  • Capability inventory: Allowed tools include WebFetch, Write, Read, and Bash.\n
  • Sanitization: Absent. No filtering or validation of the API response content is mentioned.\n- [EXTERNAL_DOWNLOADS]: Fetches building and landmark data from official NYC Open Data portals (data.cityofnewyork.us). This is a well-known service provided by the City of New York.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 12:41 PM
Security Audit — agent-trust-hub — nyc-landmarks