json-transformer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to parse and transform JSON data from external sources including local files and remote APIs. This ingestion of untrusted data creates a surface for indirect prompt injection. * Ingestion points: JSON data parsed from local files, strings, and external APIs. * Boundary markers: None; the instructions do not include specific delimiters or directives to ignore instructions embedded within the JSON content. * Capability inventory: The skill demonstrates file system access (reading and writing JSON files) and implies network access for API interactions. * Sanitization: The skill highlights structural validation using schemas (jsonschema, ajv), though this does not mitigate natural language instruction injection.
- [EXTERNAL_DOWNLOADS]: The documentation suggests the use of several third-party libraries for Python and Node.js. While these are industry-standard tools for JSON processing, they represent external dependencies that would need to be installed in the environment.
- [COMMAND_EXECUTION]: The skill provides numerous examples using the 'jq' command-line utility, including pipe operations (e.g., 'cat data.json | jq'), which involves shell command execution.
Audit Metadata