bot-developer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides developer templates and architectural guidance. The code snippets follow industry best practices, including asynchronous I/O for non-blocking operations, distributed rate limiting using Redis, and the use of parameterized database queries to prevent SQL injection.
- [INDIRECT_PROMPT_INJECTION]: The skill implements systems designed to process untrusted user input (chat messages). This attack surface is inherent to its primary purpose of building chat bots. The skill provides mitigation strategies, such as an
AutoModclass using fuzzy matching and regex to filter malicious content, and includes explicit security checklists for input sanitization and permission verification to guide developers in building secure bots.
Audit Metadata