kuroco-api-performance-review

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes API access logs and analytics data, which constitute a surface for indirect prompt injection as they ingest strings (such as User-Agents or URIs) provided by external callers.
  • Ingestion points: api_log-list and api_analytics-list tools used in the standard workflow defined in SKILL.md.
  • Boundary markers: Instructions do not explicitly define delimiters or specific warnings to ignore instructions embedded within the log data.
  • Capability inventory: The skill possesses configuration update capabilities via api-upsert_api and api-upsert_uri, although the documentation notes restrictions and requires user approval for such actions.
  • Sanitization: There is no evidence of specific escaping or filtering of log data before it is processed by the agent to generate reports.
  • [SAFE]: All external resource references are directed toward official documentation on the kuroco.app domain.
  • [SAFE]: The skill's functionality is consistent with its stated purpose as a vendor-provided diagnostic tool, utilizing official administrative interfaces for performance monitoring and usage analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 02:16 AM
Security Audit — agent-trust-hub — kuroco-api-performance-review