projects

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it fetches and displays raw project data, including names and metadata, from an external API. * Ingestion points: API responses from Layerproof endpoints (SKILL.md). * Boundary markers: Raw JSON output is wrapped in Markdown code blocks. * Capability inventory: Network operations via curl. * Sanitization: No content filtering is applied to API data before display.
  • [COMMAND_EXECUTION]: The skill performs curl commands to interact with the Layerproof API. These actions are limited to the intended API functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 04:04 PM