docyrus-app-settings
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages free-form JSON data via AppConfig and UserAppConfig. This provides a potential surface for indirect prompt injection, as an attacker with access to these configuration documents could inject instructions that the agent might inadvertently follow when processing the data.
- [COMMAND_EXECUTION]: The documentation includes instructions for using the 'docyrus curl' utility to interact with the platform's API endpoints, which is a standard part of the developer workflow for this vendor.
- [EXTERNAL_DOWNLOADS]: The skill references and depends on official vendor-provided packages including '@docyrus/app-utils' and '@docyrus/api-client'. These are recognized as legitimate resources from a trusted vendor.
Audit Metadata