local-pois

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a standard API integration for the Brave Search platform. It defines endpoints and parameters for retrieving point-of-interest (POI) data, which is a legitimate and intended use case for a search-capable agent.- [CREDENTIALS_UNSAFE]: The skill correctly uses an environment variable placeholder ${BRAVE_SEARCH_API_KEY} in its implementation examples. This follows security best practices for avoiding hardcoded secrets and credentials.- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external search results, creating a potential surface for indirect prompt injection from third-party business descriptions or reviews.
  • Ingestion points: Business titles, descriptions, and user reviews fetched from https://api.search.brave.com/res/v1/local/pois.
  • Boundary markers: The skill does not define specific delimiters for separating API content from instructions, but it treats the data as structured JSON.
  • Capability inventory: The skill's primary function is data retrieval for display; it does not possess high-privilege capabilities (like writing to the file system or executing shell commands) that could be triggered by the ingested data.
  • Sanitization: Data sanitization and instruction filtering are handled at the agent's interaction layer rather than within the skill's API specification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:26 PM
Security Audit — agent-trust-hub — local-pois