encrypted-maps
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCEEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for storing and retrieving user-controlled data, which represents a potential injection surface if the data is processed by an AI agent or application without proper sanitization.
- Ingestion points: User-supplied values and keys are ingested via frontend methods like
setValueand backend endpoints such asinsert_encrypted_value_with_metadata. - Boundary markers: The implementation relies on the
ic-vetkeyslibrary's internal access control and client-side encryption. No explicit input validation or boundary markers for the data content are demonstrated in the snippets. - Capability inventory: The skill facilitates writing to canister stable memory and performing network operations via the Internet Computer's
HttpAgent. - Sanitization: There is no mention of sanitization or escaping of the stored data in the provided documentation.
- [PERSISTENCE]: The skill utilizes browser storage for cryptographic material to enable cross-session persistence, which is a standard requirement for the described use case.
- Evidence: The frontend implementation uses
IndexedDbDerivedKeyMaterialCacheto store derived key material in IndexedDB. - Mitigation: The skill includes clear instructions to call
clearCache()during logout or identity switches to ensure sensitive key material does not persist beyond the active session. - [EXTERNAL_DOWNLOADS]: The skill references several external packages for frontend and backend development within the vendor's ecosystem.
- Evidence: Dependencies include
@icp-sdk/vetkeys,@icp-sdk/core, and the Rust/Motoko libraryic-vetkeys. - Context: The skill provides guidance on migrating from legacy
@dfinity/namespaces to current@icp-sdk/packages, consistent with the vendor's updated SDK structure.
Audit Metadata