api-integration
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the standard Python library
requestsfor HTTP operations and the vendor-scoped Node.js package@autumnsgrove/latticefor structured error handling and UI feedback in web applications. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external REST APIs, such as GitHub and OpenWeather. Processing unvalidated content from external third-party services represents a potential attack surface for indirect prompt injection.
- Ingestion points:
api_requestandfetch_all_pagesfunctions inSKILL.mdretrieve external JSON data. - Boundary markers: The provided code snippets do not include explicit boundary markers or instructions to ignore embedded prompts in the fetched data.
- Capability inventory: The skill uses
requests.getfor network access andjson.loadfor file reading inSKILL.md. - Sanitization: The snippets show basic JSON parsing but do not include specific sanitization or validation of the content returned by the external APIs.
Audit Metadata