docyrus-app-settings

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill manages free-form JSON data via AppConfig and UserAppConfig. This provides a potential surface for indirect prompt injection, as an attacker with access to these configuration documents could inject instructions that the agent might inadvertently follow when processing the data.
  • [COMMAND_EXECUTION]: The documentation includes instructions for using the 'docyrus curl' utility to interact with the platform's API endpoints, which is a standard part of the developer workflow for this vendor.
  • [EXTERNAL_DOWNLOADS]: The skill references and depends on official vendor-provided packages including '@docyrus/app-utils' and '@docyrus/api-client'. These are recognized as legitimate resources from a trusted vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:24 AM
Security Audit — agent-trust-hub — docyrus-app-settings