nyc-landmarks
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill ingests data from external APIs which could contain malicious instructions (Indirect Prompt Injection).\n
- Ingestion points: SKILL.md fetches data from data.cityofnewyork.us/resource/64uk-42ks.json and data.cityofnewyork.us/resource/buis-pvji.json.\n
- Boundary markers: Absent. No specific delimiters are used to wrap the external content.\n
- Capability inventory: Allowed tools include WebFetch, Write, Read, and Bash.\n
- Sanitization: Absent. No filtering or validation of the API response content is mentioned.\n- [EXTERNAL_DOWNLOADS]: Fetches building and landmark data from official NYC Open Data portals (data.cityofnewyork.us). This is a well-known service provided by the City of New York.
Audit Metadata