extension-oql

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables an agent to process and query structured data from canisters and CSV files, which serves as a potential surface for indirect prompt injection.\n
  • Ingestion points: Canister data accessed via OQL endpoints and local CSV files.\n
  • Boundary markers: Access control is managed through per-entity authorization levels (.public_, .controllerOnly, .scopedPerUser).\n
  • Capability inventory: Includes the ability to execute the icp command-line tool and read/write files during the ingestion process.\n
  • Sanitization: Data is parsed using standard CSV rules and escaped for Candid text format before being sent to the canister.\n- [COMMAND_EXECUTION]: The provided ingest.mjs script executes the icp command-line tool to perform canister calls.\n
  • The script uses node:child_process.execFile to interact with the Internet Computer platform.\n
  • Potential command injection is mitigated by validation of the canister principal/name and the use of argument arrays rather than shell strings.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes the caffeineai-oql library, a Motoko package provided by the vendor.\n
  • Setup instructions include fetching the dependency via the Mops package manager.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:12 PM
Security Audit — agent-trust-hub — extension-oql