https-outcalls
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external web APIs (
api.coingecko.com,httpbin.org), which introduces a surface for indirect prompt injection. Malicious data returned by these external services could potentially influence the agent's behavior if not correctly delimited from instructions. - Ingestion points: The
response.bodyis read and processed in the MotokogetIcpPriceUsdand Rustfetch_priceexamples (SKILL.md). - Boundary markers: The code examples do not explicitly implement boundary markers or instructions to ignore embedded prompts within the retrieved HTTP body.
- Capability inventory: The skill utilizes
Call.httpRequest(Motoko) andic_cdk::management_canister::http_request(Rust) to perform network operations and can influence canister state based on the results. - Sanitization: While the examples show parsing JSON data, there is no explicit sanitization of the content to prevent instructions embedded in the external data from being interpreted by the agent.
- [EXTERNAL_DOWNLOADS]: The skill documents and provides code for fetching data from external domains (
api.coingecko.comandhttpbin.org). These are well-known services commonly used for financial price data and HTTP request testing respectively, and the network operations trace back to the vendor's documented platform functionality.
Audit Metadata