apiiro-fix
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to execute vendor-specific CLI commands, including
apiiro risks remediateandapiiro guardian query, to perform security remediation tasks. - [PROMPT_INJECTION]: The skill instructions create an indirect prompt injection surface by directing the agent to take content from tool outputs (remediation prompts or AI guidance) and apply it directly as code changes. * Ingestion points: Output from the
apiiro risks remediateandapiiro guardian querycommands referenced in SKILL.md. * Boundary markers: None identified; the instructions suggest the agent apply fix prompts directly if theis_promptflag is true. * Capability inventory: The agent is expected to perform code modifications based on the external input received from the CLI. * Sanitization: No explicit sanitization, validation, or human-in-the-loop verification of the external guidance is mentioned in the skill workflow.
Audit Metadata