auth-md
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The evaluation script
evals/test_probe.pyusessubprocess.runto execute the local discovery scriptscripts/probe_auth_md.pyduring automated testing. This is a standard testing practice to verify the probe's logic and does not pose a threat to the user's environment. - [EXTERNAL_DOWNLOADS]: The
scripts/probe_auth_md.pyutility performs network requests (HTTP GET/HEAD) to fetch OAuth and protected resource metadata from remote servers. This is required for the skill's purpose of protocol discovery. The script includes significant security controls, such as aNetworkPolicythat defaults to blocking private, loopback (except for localhost), and multicast IP addresses to prevent SSRF, and it forbids the use of credentials within URLs. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process metadata from external, potentially untrusted servers. A malicious server could provide crafted JSON metadata or prose in the
agent_auth.skillfield. However, the skill instructions explicitly warn the agent to treat these external documents as untrusted input and not as executable instructions. Mandatory evidence for this surface: - Ingestion points: Remote metadata URLs processed by
scripts/probe_auth_md.pyand subsequently analyzed by the agent. - Boundary markers: The agent is instructed to use a specific checklist-based 'safety verdict' before proceeding with implementation code.
- Capability inventory: The agent can perform network discovery via the included script and suggest architectural/code changes to the user.
- Sanitization: The probe script enforces response size limits (default 1MB) and validates content types to prevent processing of malicious payloads.
Audit Metadata