skills/bankrbot/skills/cortx/Gen Agent Trust Hub

cortx

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates a potential attack surface through its ingestion of remote JSON data from the CORTX API.
  • Ingestion points: Reliability data is retrieved from https://usecortx.dev/api/v1/reliability/{serviceId} (SKILL.md).
  • Boundary markers: The skill defines comprehensive 'Response validation' and 'Resource binding' procedures to verify that the returned data is properly formatted and belongs to the intended service.
  • Capability inventory: The skill is strictly limited to an advisory role and is forbidden from authorizing payments, triggering wallet actions, or executing commands found in the response fields.
  • Sanitization: All input fields are subjected to strict type checking, enum enforcement, and numeric range validation to prevent schema confusion and malicious interpolation.
  • [SAFE]: The skill uses established vendor resources, including its own API domain and GitHub repositories. It follows a 'fail closed' approach for validation failures and prioritizes local agent controls over remote advisory signals.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:46 AM
Security Audit — agent-trust-hub — cortx