narova-stock-extensions
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill interacts with reputable media providers (e.g., NASA, Wikimedia, Smithsonian) and correctly references environment variables for API key management rather than hardcoding sensitive credentials.- [PROMPT_INJECTION]: The skill workflow involves browsing and inspecting external web pages for asset metadata, which creates a surface for indirect prompt injection. \n
- Ingestion points: SKILL.md (Step 5: 'Inspect the exact item page') and references/providers.md ('Use the item page/browser workflow'). \n
- Boundary markers: The instructions do not define explicit delimiters to isolate external content. \n
- Capability inventory: narova assets download and narova assets import in SKILL.md. \n
- Sanitization: No specific filtering or sanitization of external page content is defined before it is processed by the agent.- [COMMAND_EXECUTION]: The skill provides shell command templates for downloading assets via a local CLI tool using external URLs. This pattern relies on the underlying CLI implementation to safely handle untrusted input strings.
Audit Metadata