claude-api

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references standard installation procedures for official Anthropic SDKs (the 'anthropic' Python package and '@anthropic-ai/sdk' Node.js package).- [PROMPT_INJECTION]: The provided code snippets demonstrate the ingestion of external data (text messages and base64-encoded images) into API calls without explicit input validation, sanitization, or boundary markers. While common in integration documentation, this creates a surface for potential indirect prompt injection. Findings: 1. Ingestion points: 'messages' content and image data read from 'diagram.png'. 2. Boundary markers: None present in code samples. 3. Capability inventory: Network communication with the Anthropic API. 4. Sanitization: No input validation logic is included in the patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — claude-api