anthropic-tool-use-runtime

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly recognizes the risk of prompt injection and implements defensive measures. It instructs that tool calls proposed by the model are 'untrusted model output' and mandates that authorization logic reside in the code adapter rather than the prompt instructions.
  • [DATA_EXFILTRATION]: The skill enforces strong data protection policies. It requires redaction of PII and secrets from logs and audit records, and specifically instructs that API credentials must be injected at deployment time rather than committed to source code.
  • [COMMAND_EXECUTION]: The skill manages tool execution (which may include system commands) through a strict 'fail-closed' adapter. It mandates argument validation against approved schemas and requires an authorization check against the user's principal identity before any side-effecting action is taken.
  • [EXTERNAL_DOWNLOADS]: The skill addresses Model Context Protocol (MCP) connectors, characterizing them as remote side-effecting surfaces. It requires explicit architectural approval for each connector and applies the same rigorous authorization and auditing rules to them as to local tools.
  • [SAFE]: The skill incorporates industry best practices for agentic security, including idempotency keys for mutating actions to prevent duplicate executions during retries and bounded tool-calling loops to prevent infinite execution chains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — anthropic-tool-use-runtime