cortx
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates a potential attack surface through its ingestion of remote JSON data from the CORTX API.
- Ingestion points: Reliability data is retrieved from
https://usecortx.dev/api/v1/reliability/{serviceId}(SKILL.md). - Boundary markers: The skill defines comprehensive 'Response validation' and 'Resource binding' procedures to verify that the returned data is properly formatted and belongs to the intended service.
- Capability inventory: The skill is strictly limited to an advisory role and is forbidden from authorizing payments, triggering wallet actions, or executing commands found in the response fields.
- Sanitization: All input fields are subjected to strict type checking, enum enforcement, and numeric range validation to prevent schema confusion and malicious interpolation.
- [SAFE]: The skill uses established vendor resources, including its own API domain and GitHub repositories. It follows a 'fail closed' approach for validation failures and prioritizes local agent controls over remote advisory signals.
Audit Metadata