device-authorization
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill initiates network requests to
auth.sigmaidentity.comto retrieve authorization codes and user tokens. While this is the intended functionality of the documented OAuth flow, these requests are directed to an external domain that is not on the standard whitelist. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external user profile data (such as names and emails) from the Sigma Identity API, which could potentially contain malicious instructions if the data source were compromised.
- Ingestion points:
SKILL.md(fetches user information via the/api/auth/oauth2/userinfoendpoint in Step 4). - Boundary markers: Absent; there are no delimiters or explicit instructions to the agent to ignore potentially malicious content within the fetched data.
- Capability inventory: The skill uses
fetchfor network operations, console logging, and provides examples for opening URLs in a web browser via shell plugins. - Sanitization: Absent; the provided code snippets return the raw JSON response from the API without any escaping or validation of the content.
Audit Metadata