fingerprint-node
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill correctly handles sensitive credentials by instructing the user to store the 'FINGERPRINT_SECRET_API_KEY' in environment variables and using the 'dotenv' library for server-side loading, preventing credential exposure.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a pattern for processing untrusted data (event identifiers) from the frontend. 1. Ingestion points: 'eventId' parameter in 'verifyEvent' function (snippets/verify.js). 2. Boundary markers: No explicit prompt boundary markers are present as the data is processed programmatically. 3. Capability inventory: The skill performs a network lookup using the 'eventId' via 'fingerprint.getEvent' (snippets/verify.js). 4. Sanitization: The code validates that 'eventId' is present before execution. This represents a standard security verification flow and is not considered a high-risk injection surface.\n- [SAFE]: The server-side verification logic incorporates essential security checks, including event timestamp validation for replay protection, identification confidence score thresholds, and evaluation of Smart Signals to detect bots, VPNs, proxies, and browser tampering.
Audit Metadata