api-to-agent-cli
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a security-focused guide and reference project for developers. It implements defensive programming standards throughout its reference code, such as strict input validation and structured error handling to prevent common agent failure modes.
- [INDIRECT_PROMPT_INJECTION]: The skill reference implementation (
hello-cli) includes an ingestion surface for external data via CLI flags and raw JSON payloads. - Ingestion points: User input is accepted through the
--title,--notes, and--jsonflags inassets/example-hello-cli/src/hello_cli/commands/todos.py. - Boundary markers: The skill documentation emphasizes structured JSON output for tool responses and utilizes clear SKILL.md guidelines to define the agent's operational boundaries.
- Capability inventory: The CLI is capable of modifying local state via the
store.pymodule and executing multi-step business workflows inworkflows.py. - Sanitization: The framework implements proactive input hardening in
assets/example-hello-cli/src/hello_cli/core/validate.py, which canonicalizes inputs, enforces length limits, and rejects control characters or suspicious URL fragments to mitigate potential injection or hallucination attacks.
Audit Metadata