skills/dfinity/icskills/ic-dashboard/Gen Agent Trust Hub

ic-dashboard

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill extensively uses curl to interact with various public REST API endpoints hosted on internetcomputer.org subdomains (e.g., ic-api, icrc-api, ledger-api). These commands are used to fetch read-only data such as canister metadata, transaction logs, and network metrics.
  • [REMOTE_CODE_EXECUTION]: The SKILL.md file contains a verification command that pipes the output of an OpenAPI JSON file into a Python one-liner: curl -s "https://ic-api.internetcomputer.org/api/v3/openapi.json" | python3 -c "import sys,json; json.load(sys.stdin); print('OK')". While piping to an interpreter is a high-risk pattern, this specific instance is a static check that validates JSON structure using the Python standard library and targets the vendor's official infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from several API endpoints, creating an indirect prompt injection surface.
  • Ingestion points: Data is ingested from multiple DFINITY-owned REST APIs listed in the Base URLs table in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands within the fetched JSON data.
  • Capability inventory: The skill's primary capability is network communication via curl.
  • Sanitization: There is no logic provided to sanitize or filter the API responses before they are processed by the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: https://ic-api.internetcomputer.org/api/v3/openapi.json - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 02:49 PM
Security Audit — agent-trust-hub — ic-dashboard