service-discoverability
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing official developer tools from the
@icp-sdkand@dfinitynamespaces via NPM, such as@icp-sdk/icp-cliand@icp-sdk/ic-wasm. These packages are part of the standard DFINITY development environment and are required for managing canister applications. - [INDIRECT_PROMPT_INJECTION]: The skill establishes several surfaces where data could be processed by an agent, such as the
getApiDocquery method and the OQLexecutemethod. The documentation explicitly warns developers that these surfaces must not contain instructions meant to manipulate or override an assistant's safety guidelines, effectively addressing potential prompt injection vectors in application metadata. Ingestion points include the manifest file and API documentation methods, while the capability inventory includes the ability for authorized agents to perform state-changing update calls. - [COMMAND_EXECUTION]: The skill provides examples of shell commands for use in
presyncdeployment hooks, includingenvsubstandicp canister status. These commands are used to dynamically resolve canister identifiers at deploy time, ensuring that environment-specific configuration is correctly injected without hard-coding sensitive values.
Audit Metadata