narova-stock-extensions

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill interacts with reputable media providers (e.g., NASA, Wikimedia, Smithsonian) and correctly references environment variables for API key management rather than hardcoding sensitive credentials.- [PROMPT_INJECTION]: The skill workflow involves browsing and inspecting external web pages for asset metadata, which creates a surface for indirect prompt injection. \n
  • Ingestion points: SKILL.md (Step 5: 'Inspect the exact item page') and references/providers.md ('Use the item page/browser workflow'). \n
  • Boundary markers: The instructions do not define explicit delimiters to isolate external content. \n
  • Capability inventory: narova assets download and narova assets import in SKILL.md. \n
  • Sanitization: No specific filtering or sanitization of external page content is defined before it is processed by the agent.- [COMMAND_EXECUTION]: The skill provides shell command templates for downloading assets via a local CLI tool using external URLs. This pattern relies on the underlying CLI implementation to safely handle untrusted input strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 02:06 AM
Security Audit — agent-trust-hub — narova-stock-extensions