audn-compliance-report
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill interacts exclusively with the vendor's official domain (audn.ai) for report generation and status polling.
- [SAFE]: Sensitive credentials (AUDN_API_TOKEN) are managed through environment variables rather than hardcoded strings, following industry security standards.
- [PROMPT_INJECTION]: The skill retrieves data from external API responses (campaign results and metadata) to generate a summary, which serves as an ingestion point for indirect prompt injection. Ingestion point: API response metadata in SKILL.md. Boundary markers: Absent. Capability inventory: HTTP GET and POST requests to the vendor API. Sanitization: Absent. This finding is considered safe as the skill has no access to sensitive local resources or dangerous system commands.
Audit Metadata