agent-web-identity
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for using the
icpCLI, includingicp identity link web,icp identity list, andicp canister call. These are intended for the primary purpose of managing Internet Computer identities. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data via canister calls (
icp canister call). While it does not include an explicit injection, this represents an attack surface (Category 8c: Tool output poisoning) where responses from a malicious canister could attempt to influence the agent. The severity is low as the skill follows best practices like asking for user confirmation before state-changing calls.
Audit Metadata