openai-tool-calling-runtime
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified through the ingestion of external architectural configuration.
- Ingestion points: The skill instructions involve loading and parsing
ai-architecture.mdto identify approved tools, schemas, and authorization scopes. - Boundary markers: There are no instructions provided for using delimiters or boundary markers to isolate content when reading the configuration file.
- Capability inventory: The skill generates tool execution adapters, authorization checks, and audit logging hooks, which represent executable capabilities based on the ingested configuration.
- Sanitization: The skill incorporates strong mitigations by requiring explicit authorization and input validation before any side-effecting code is executed.
Audit Metadata