managing-frontegg

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill interacts with the well-known service provider Frontegg. All network operations are directed to the official domain api.frontegg.com and use platform-managed credentials ($FRONTEGG_VENDOR_TOKEN).
  • [PROMPT_INJECTION]: The skill processes data from external API responses, including user emails, tenant names, and audit logs. This constitutes a potential surface for indirect prompt injection where malicious content in those fields could attempt to influence the agent's subsequent actions.
  • Ingestion points: SKILL.md (via the frontegg_api helper function and Phase 1/Phase 2 scripts)
  • Boundary markers: None identified in the prompt templates
  • Capability inventory: Shell command execution via curl and data processing via jq
  • Sanitization: The skill uses jq to extract specific fields, which provides structural isolation, but it does not perform content-level sanitization of the strings retrieved from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:28 AM
Security Audit — agent-trust-hub — managing-frontegg