extension-oql
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables an agent to process and query structured data from canisters and CSV files, which serves as a potential surface for indirect prompt injection.\n
- Ingestion points: Canister data accessed via OQL endpoints and local CSV files.\n
- Boundary markers: Access control is managed through per-entity authorization levels (.public_, .controllerOnly, .scopedPerUser).\n
- Capability inventory: Includes the ability to execute the
icpcommand-line tool and read/write files during the ingestion process.\n - Sanitization: Data is parsed using standard CSV rules and escaped for Candid text format before being sent to the canister.\n- [COMMAND_EXECUTION]: The provided
ingest.mjsscript executes theicpcommand-line tool to perform canister calls.\n - The script uses
node:child_process.execFileto interact with the Internet Computer platform.\n - Potential command injection is mitigated by validation of the canister principal/name and the use of argument arrays rather than shell strings.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes the
caffeineai-oqllibrary, a Motoko package provided by the vendor.\n - Setup instructions include fetching the dependency via the Mops package manager.
Audit Metadata