Replicate Automation

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external sources, which constitutes an indirect prompt injection surface.
  • Ingestion points: Data from REPLICATE_MODELS_README_GET (model documentation), REPLICATE_MODELS_GET (schemas), and REPLICATE_MODELS_PREDICTIONS_CREATE (model outputs and logs) is brought into the agent's context.
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in the external content.
  • Capability inventory: The skill provides access to Replicate's API for running predictions, managing files, and querying model information via MCP tools. It does not have access to local shell execution or file system modification tools.
  • Sanitization: No explicit sanitization or filtering of the external content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 02:15 AM