fingerprint-python

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses environment variables (FINGERPRINT_SECRET_API_KEY) and python-dotenv for secret management, which is a standard security best practice to avoid hardcoding credentials in source code.
  • [SAFE]: External dependencies (fingerprint-server-sdk, python-dotenv) and documentation links (e.g., github.com/fingerprintjs/...) are official vendor resources or well-known libraries.
  • [SAFE]: The verification logic implemented in snippets/verify.py includes multiple security checks, such as replay protection (checking the replayed flag and timestamp age), confidence scoring, and detection of bots, VPNs, or tampering to ensure the integrity of the identification data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Fingerprint API (client.get_event(event_id) in snippets/verify.py). However, the skill treats this data as structured fields for Boolean and numeric checks rather than natural language instructions, and it includes robust validation boundaries (timestamp checks, confidence scores), minimizing the risk of exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:25 PM
Security Audit — agent-trust-hub — fingerprint-python