https-outcalls

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external web APIs (api.coingecko.com, httpbin.org), which introduces a surface for indirect prompt injection. Malicious data returned by these external services could potentially influence the agent's behavior if not correctly delimited from instructions.
  • Ingestion points: The response.body is read and processed in the Motoko getIcpPriceUsd and Rust fetch_price examples (SKILL.md).
  • Boundary markers: The code examples do not explicitly implement boundary markers or instructions to ignore embedded prompts within the retrieved HTTP body.
  • Capability inventory: The skill utilizes Call.httpRequest (Motoko) and ic_cdk::management_canister::http_request (Rust) to perform network operations and can influence canister state based on the results.
  • Sanitization: While the examples show parsing JSON data, there is no explicit sanitization of the content to prevent instructions embedded in the external data from being interpreted by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill documents and provides code for fetching data from external domains (api.coingecko.com and httpbin.org). These are well-known services commonly used for financial price data and HTTP request testing respectively, and the network operations trace back to the vendor's documented platform functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:52 AM
Security Audit — agent-trust-hub — https-outcalls