backend-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill templates the ingestion of untrusted external data through HTTP request headers and body parsing, creating a potential surface for indirect prompt injection.
- Ingestion points: The code snippets in
SKILL.mddemonstrate extracting data fromreq.headers.authorizationandreq.json(). - Boundary markers: No explicit boundary markers or instructions to disregard instructions embedded in input data are included in the templates.
- Capability inventory: The templates demonstrate capabilities including database operations via Supabase, caching via Redis, and logging to the console.
- Sanitization: The skill includes a snippet demonstrating Zod validation (
z.ZodError) for error handling, though the specific input validation schemas are left to the implementation.
Audit Metadata