api-to-agent-cli

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a security-focused guide and reference project for developers. It implements defensive programming standards throughout its reference code, such as strict input validation and structured error handling to prevent common agent failure modes.
  • [INDIRECT_PROMPT_INJECTION]: The skill reference implementation (hello-cli) includes an ingestion surface for external data via CLI flags and raw JSON payloads.
  • Ingestion points: User input is accepted through the --title, --notes, and --json flags in assets/example-hello-cli/src/hello_cli/commands/todos.py.
  • Boundary markers: The skill documentation emphasizes structured JSON output for tool responses and utilizes clear SKILL.md guidelines to define the agent's operational boundaries.
  • Capability inventory: The CLI is capable of modifying local state via the store.py module and executing multi-step business workflows in workflows.py.
  • Sanitization: The framework implements proactive input hardening in assets/example-hello-cli/src/hello_cli/core/validate.py, which canonicalizes inputs, enforces length limits, and rejects control characters or suspicious URL fragments to mitigate potential injection or hallucination attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 05:35 AM