service-discoverability

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing official developer tools from the @icp-sdk and @dfinity namespaces via NPM, such as @icp-sdk/icp-cli and @icp-sdk/ic-wasm. These packages are part of the standard DFINITY development environment and are required for managing canister applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes several surfaces where data could be processed by an agent, such as the getApiDoc query method and the OQL execute method. The documentation explicitly warns developers that these surfaces must not contain instructions meant to manipulate or override an assistant's safety guidelines, effectively addressing potential prompt injection vectors in application metadata. Ingestion points include the manifest file and API documentation methods, while the capability inventory includes the ability for authorized agents to perform state-changing update calls.
  • [COMMAND_EXECUTION]: The skill provides examples of shell commands for use in presync deployment hooks, including envsubst and icp canister status. These commands are used to dynamically resolve canister identifiers at deploy time, ensuring that environment-specific configuration is correctly injected without hard-coding sensitive values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 11:04 PM
Security Audit — agent-trust-hub — service-discoverability