api-gateway

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill's architecture is designed to ingest data from many external platforms such as Gmail, Slack, and Notion, which provides a significant surface for indirect prompt injection. Malicious instructions could be embedded in external data and processed by the AI agent without proper sanitization. No specific boundary markers or instruction-filtering guidelines are present in the documentation.
  • [NO_CODE]: This skill package does not contain any executable code files; it is composed of markdown-based routing references and associated metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 12:15 AM
Security Audit — agent-trust-hub — api-gateway