encrypted-maps

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCEEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for storing and retrieving user-controlled data, which represents a potential injection surface if the data is processed by an AI agent or application without proper sanitization.
  • Ingestion points: User-supplied values and keys are ingested via frontend methods like setValue and backend endpoints such as insert_encrypted_value_with_metadata.
  • Boundary markers: The implementation relies on the ic-vetkeys library's internal access control and client-side encryption. No explicit input validation or boundary markers for the data content are demonstrated in the snippets.
  • Capability inventory: The skill facilitates writing to canister stable memory and performing network operations via the Internet Computer's HttpAgent.
  • Sanitization: There is no mention of sanitization or escaping of the stored data in the provided documentation.
  • [PERSISTENCE]: The skill utilizes browser storage for cryptographic material to enable cross-session persistence, which is a standard requirement for the described use case.
  • Evidence: The frontend implementation uses IndexedDbDerivedKeyMaterialCache to store derived key material in IndexedDB.
  • Mitigation: The skill includes clear instructions to call clearCache() during logout or identity switches to ensure sensitive key material does not persist beyond the active session.
  • [EXTERNAL_DOWNLOADS]: The skill references several external packages for frontend and backend development within the vendor's ecosystem.
  • Evidence: Dependencies include @icp-sdk/vetkeys, @icp-sdk/core, and the Rust/Motoko library ic-vetkeys.
  • Context: The skill provides guidance on migrating from legacy @dfinity/ namespaces to current @icp-sdk/ packages, consistent with the vendor's updated SDK structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 11:05 PM
Security Audit — agent-trust-hub — encrypted-maps