ic-dashboard
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill extensively uses
curlto interact with various public REST API endpoints hosted oninternetcomputer.orgsubdomains (e.g.,ic-api,icrc-api,ledger-api). These commands are used to fetch read-only data such as canister metadata, transaction logs, and network metrics. - [REMOTE_CODE_EXECUTION]: The
SKILL.mdfile contains a verification command that pipes the output of an OpenAPI JSON file into a Python one-liner:curl -s "https://ic-api.internetcomputer.org/api/v3/openapi.json" | python3 -c "import sys,json; json.load(sys.stdin); print('OK')". While piping to an interpreter is a high-risk pattern, this specific instance is a static check that validates JSON structure using the Python standard library and targets the vendor's official infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from several API endpoints, creating an indirect prompt injection surface.
- Ingestion points: Data is ingested from multiple DFINITY-owned REST APIs listed in the Base URLs table in
SKILL.md. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands within the fetched JSON data.
- Capability inventory: The skill's primary capability is network communication via
curl. - Sanitization: There is no logic provided to sanitize or filter the API responses before they are processed by the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://ic-api.internetcomputer.org/api/v3/openapi.json - DO NOT USE without thorough review
Audit Metadata