chat-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of chat bots that ingest untrusted content from external messaging platforms, creating a potential surface for indirect prompt injection attacks where malicious instructions in chat messages could influence agent behavior.
- Ingestion points: The skill defines event handlers such as
onNewMention,onDirectMessage, andonSubscribedMessageinSKILL.mdthat ingest externalmessage.textdata from chat platforms. - Boundary markers: The provided implementation examples do not demonstrate the use of delimiters, XML tags, or explicit instructions to the AI agent to ignore potentially malicious embedded commands within user messages.
- Capability inventory: The framework includes capabilities across all adapters for posting content to threads, streaming AI responses, and persisting data via state adapters.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the
message.textcontent in the documentation before it is passed to LLM agents for processing.
Audit Metadata