build-with-cracked
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and processing data from over 60,000 external tools, including social media platforms and web scrapers, which creates a significant surface for indirect prompt injection if the retrieved content contains malicious instructions.\n
- Ingestion points: The agent receives external data through the results of the
POST /v1/runendpoint.\n - Boundary markers: There are no explicit delimiters or specific instructions for the agent to disregard instructions embedded within the retrieved tool outputs.\n
- Capability inventory: The skill includes functionality for network interaction via various tools and file management through a dedicated workspace (
/v1/files).\n - Sanitization: The documentation does not specify sanitization or escaping procedures for external content prior to agent processing.\n- [EXTERNAL_DOWNLOADS]: The skill documentation refers to several vendor-specific packages and resources required for operation.\n
- Python packages: Includes
cracked-ai,cracked-ai-langchain,cracked-ai-crewai, andcracked-ai-openai-agents.\n - Node.js packages: Includes
cracked-ai-sdkandcracked-ai-vercel.\n - External references: Links to official documentation, schemas, and live skill definitions hosted on
cracked.ai.
Audit Metadata