hydro-plugin-services

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The documentation defines APIs that ingest untrusted external data and provide powerful capabilities for file manipulation and network interaction.
  • Ingestion points: Data received via OAuthProvider.callback and file uploads through StorageModel.put (SKILL.md).
  • Boundary markers: Not explicitly specified within the API documentation context.
  • Capability inventory: File system access (StorageModel), network requests (superagent), and task persistence (TaskModel, ScheduleModel) (SKILL.md).
  • Sanitization: Recommends using Schemastery for input validation and TokenModel for state verification.
  • [COMMAND_EXECUTION]: Describes programmatic access to the local filesystem and S3-compatible storage via the StorageModel and LocalStorageService APIs.
  • [CREDENTIALS_UNSAFE]: Contains detailed instructions on how to handle API keys and secrets securely, specifically demonstrating the use of role('secret') in schemas and the FLAG_SECRET flag to ensure sensitive values are encrypted at rest and masked in management interfaces.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:26 AM
Security Audit — agent-trust-hub — hydro-plugin-services