display-access

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill defines patterns for processing external data via media URLs, such as Image(uri: ...) and VideoPlayer(provider: .uri(...)), which are rendered on the wearable device. This represents an ingestion point for external content into the agent's operating context.
  • The documentation notes that the library includes validation to ensure URLs use HTTP(S) protocols, which helps mitigate some basic injection vectors.
  • As a security consideration, developers should implement additional sanitization or validation if these URLs are sourced from untrusted inputs to prevent potential indirect injection via malicious media metadata or content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 07:31 PM