voice-ai-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides code patterns for creating webhooks that process external event data and user transcriptions to trigger internal business logic. This pattern establishes an indirect prompt injection surface where maliciously crafted speech or metadata could attempt to manipulate the agent's function calling behavior.\n
- Ingestion points: The
/vapi/webhookendpoint inSKILL.mdingests JSON payloads from an external provider (Vapi).\n - Boundary markers: The examples do not include explicit instructions or markers to distinguish between legitimate user data and potential adversarial instructions within the transcription field.\n
- Capability inventory: The skill demonstrates capabilities for executing backend tools (
check_order), writing to storage (save_transcript), and initiating network calls through provider APIs.\n - Sanitization: The provided logic lacks input validation or sanitization for the parameters extracted from the external webhook data.
Audit Metadata