fingerprint-python
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses environment variables (
FINGERPRINT_SECRET_API_KEY) andpython-dotenvfor secret management, which is a standard security best practice to avoid hardcoding credentials in source code. - [SAFE]: External dependencies (
fingerprint-server-sdk,python-dotenv) and documentation links (e.g.,github.com/fingerprintjs/...) are official vendor resources or well-known libraries. - [SAFE]: The verification logic implemented in
snippets/verify.pyincludes multiple security checks, such as replay protection (checking thereplayedflag andtimestampage), confidence scoring, and detection of bots, VPNs, or tampering to ensure the integrity of the identification data. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Fingerprint API (
client.get_event(event_id)insnippets/verify.py). However, the skill treats this data as structured fields for Boolean and numeric checks rather than natural language instructions, and it includes robust validation boundaries (timestamp checks, confidence scores), minimizing the risk of exploitation.
Audit Metadata