extension-querying-oql
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates interaction with the Internet Computer
icpCLI tool to execute canister calls. It includes specific, proactive guidance on how to escape JSON strings (\") and handle single quotes for shell safety ('\'') when constructing command arguments from potential user inputs. - [INDIRECT_PROMPT_INJECTION]: The skill defines a protocol for mapping user requirements to structured OQL queries, which involves processing external data. It follows security best practices by defining clear boundary markers (wrapping JSON in specific Candid text literal containers) and providing sanitization steps for various data types. Evidence: (1) Ingestion points: User-provided search terms and filter values documented in query examples. (2) Boundary markers: Instructions to wrap JSON queries in specific
("...")literals. (3) Capability inventory: Shell execution oficp canister callforschemaandexecutemethods. (4) Sanitization: Explicit instructions for escaping double quotes within JSON and shell-level single quote escaping are included.
Audit Metadata