display-access
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill defines patterns for processing external data via media URLs, such as
Image(uri: ...)andVideoPlayer(provider: .uri(...)), which are rendered on the wearable device. This represents an ingestion point for external content into the agent's operating context. - The documentation notes that the library includes validation to ensure URLs use HTTP(S) protocols, which helps mitigate some basic injection vectors.
- As a security consideration, developers should implement additional sanitization or validation if these URLs are sourced from untrusted inputs to prevent potential indirect injection via malicious media metadata or content.
Audit Metadata