asc-metrics
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources that could theoreticaly contain malicious instructions.
- Ingestion points: Reads
app-marketing-context.mdand processes JSON responses fromappeeky.comAPI endpoints. - Boundary markers: None identified.
- Capability inventory: The skill only performs read-only operations and data summarization; it has no capabilities for file writing, shell command execution, or network exfiltration to third-party domains.
- Sanitization: Standard LLM processing is utilized for generating analytical reports from the data.
- [SAFE]: The skill utilizes vendor-authorized API endpoints (
appeeky.com) to retrieve the user's performance metrics for the intended analytical purpose. No patterns of obfuscation, privilege escalation, or persistence were found. All network operations are directed at the author's own infrastructure.
Audit Metadata