ops-integrate
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses web search results to identify API endpoints where it subsequently sends user credentials for connectivity testing. This creates a surface for attackers to intercept keys by poisoning search results.
- Ingestion points: The
WebSearchtool is used in Step 1 to discover the base URL and health endpoints for a given service. - Boundary markers: Step 2 requires the user to confirm the discovered URLs via
AskUserQuestion, providing a manual verification step, though no technical delimiters are used to separate search data from instructions. - Capability inventory: The skill has access to the
Bashtool (forcurlandjqoperations),Read,Write, andEdittools. - Sanitization: No automated filtering or validation is performed on the URLs discovered via search before they are used in network requests.
- [COMMAND_EXECUTION]: The skill executes shell commands (via
curlandjq) that incorporate variables derived from externally sourced data. - The
curlcommand in Step 4 uses HTTP headers to transmit user credentials to aBASE_URLandHEALTH_ENDPOINTderived from potentially untrusted web search results. - The skill performs file operations using
jqto manage a localpreferences.jsonfile, which involves writing and reading user credentials and service definitions.
Audit Metadata