recipes
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill exclusively references official Deepgram GitHub repositories and domains for code snippets and coverage information.
- [SAFE]: The instructions explicitly state that recipes should read the DEEPGRAM_API_KEY from environment variables, which is a security best practice to avoid hardcoded credentials.
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest content from external sources (GitHub) to provide recipes to the user.
- Ingestion points: The agent reads file content (examples, tests, and READMEs) from the
deepgram/recipesrepository. - Boundary markers: The skill does not define specific delimiters for the external content; it relies on the agent platform's native handling of external data.
- Capability inventory: The skill provides instructions for the agent to find and display code; it does not request capabilities for file writing, system modifications, or arbitrary network access.
- Sanitization: No explicit sanitization of the retrieved repository content is performed by the skill instructions.
Audit Metadata