ops-integrate

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill uses web search results to identify API endpoints where it subsequently sends user credentials for connectivity testing. This creates a surface for attackers to intercept keys by poisoning search results.
  • Ingestion points: The WebSearch tool is used in Step 1 to discover the base URL and health endpoints for a given service.
  • Boundary markers: Step 2 requires the user to confirm the discovered URLs via AskUserQuestion, providing a manual verification step, though no technical delimiters are used to separate search data from instructions.
  • Capability inventory: The skill has access to the Bash tool (for curl and jq operations), Read, Write, and Edit tools.
  • Sanitization: No automated filtering or validation is performed on the URLs discovered via search before they are used in network requests.
  • [COMMAND_EXECUTION]: The skill executes shell commands (via curl and jq) that incorporate variables derived from externally sourced data.
  • The curl command in Step 4 uses HTTP headers to transmit user credentials to a BASE_URL and HEALTH_ENDPOINT derived from potentially untrusted web search results.
  • The skill performs file operations using jq to manage a local preferences.json file, which involves writing and reading user credentials and service definitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:52 PM