claude-api
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references standard installation procedures for official Anthropic SDKs (the 'anthropic' Python package and '@anthropic-ai/sdk' Node.js package).- [PROMPT_INJECTION]: The provided code snippets demonstrate the ingestion of external data (text messages and base64-encoded images) into API calls without explicit input validation, sanitization, or boundary markers. While common in integration documentation, this creates a surface for potential indirect prompt injection. Findings: 1. Ingestion points: 'messages' content and image data read from 'diagram.png'. 2. Boundary markers: None present in code samples. 3. Capability inventory: Network communication with the Anthropic API. 4. Sanitization: No input validation logic is included in the patterns.
Audit Metadata