api-integration

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the standard Python library requests for HTTP operations and the vendor-scoped Node.js package @autumnsgrove/lattice for structured error handling and UI feedback in web applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external REST APIs, such as GitHub and OpenWeather. Processing unvalidated content from external third-party services represents a potential attack surface for indirect prompt injection.
  • Ingestion points: api_request and fetch_all_pages functions in SKILL.md retrieve external JSON data.
  • Boundary markers: The provided code snippets do not include explicit boundary markers or instructions to ignore embedded prompts in the fetched data.
  • Capability inventory: The skill uses requests.get for network access and json.load for file reading in SKILL.md.
  • Sanitization: The snippets show basic JSON parsing but do not include specific sanitization or validation of the content returned by the external APIs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:32 AM
Security Audit — agent-trust-hub — api-integration