extension-querying-oql

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates interaction with the Internet Computer icp CLI tool to execute canister calls. It includes specific, proactive guidance on how to escape JSON strings (\") and handle single quotes for shell safety ('\'') when constructing command arguments from potential user inputs.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a protocol for mapping user requirements to structured OQL queries, which involves processing external data. It follows security best practices by defining clear boundary markers (wrapping JSON in specific Candid text literal containers) and providing sanitization steps for various data types. Evidence: (1) Ingestion points: User-provided search terms and filter values documented in query examples. (2) Boundary markers: Instructions to wrap JSON queries in specific ("...") literals. (3) Capability inventory: Shell execution of icp canister call for schema and execute methods. (4) Sanitization: Explicit instructions for escaping double quotes within JSON and shell-level single quote escaping are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:01 PM
Security Audit — agent-trust-hub — extension-querying-oql